Vulnerability

CVE-2025-22869
CVSS Score 6.9 medium

CVSS Vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

CWE

CWE-770

[CVE-2025-22869] CWE-770: Allocation of Resources Without Limits or Throttling

Description

SSH servers which implement file transfer protocols are vulnerable to a denial of service attack from clients which complete the key exchange slowly, or not at all, causing pending content to be read into memory, but never transmitted.

See golang.org/x/crypto package information