CVE-2025-47908

Aliases:GHSA-mh55-gqvf-xfwmGO-2024-2883CGA-2pxr-7p5m-7mchCGA-4985-x2hx-w658CGA-4mmm-73g4-p5rmCGA-567v-59h5-h69hCGA-5jjj-jgcj-vx23CGA-6g87-cgr6-9679CGA-7r36-6h9p-5p5rCGA-9657-r7q5-2jq9CGA-96mc-fxqv-cq6cCGA-c43c-c6x6-m374CGA-chhw-984c-9838CGA-crj4-7v9c-2mxhCGA-cx9r-p77h-cpw9CGA-f2xr-3wh3-q6g6CGA-fjxm-27fj-wh49CGA-hwmx-vjpm-xq72CGA-j55g-f25w-2pq6CGA-jh27-vwwq-g75wCGA-jrqw-9wm5-f3mgCGA-m56c-xjc3-crq3CGA-pf2j-cj7h-29cpCGA-pg34-3hr8-gp32CGA-3h86-rjg7-27h5CGA-3hm9-q472-pfpfCGA-47mc-wxjp-ph2mCGA-4cww-vm7m-3jx5CGA-5385-v3x2-9pxqCGA-7c3q-p774-gvhqCGA-7qwr-6q6q-9x9fCGA-8q2j-jp6m-m6m5CGA-chmw-52h3-wj36CGA-g7c2-6x42-7x3hCGA-g7fj-qjvw-jjcjCGA-hvgm-3m22-fjfcCGA-jpq6-8pxf-xw27CGA-jqr9-ccxp-3366CGA-mgcq-9c5w-hqr8CGA-mwxm-5rcp-v68qCGA-pgxg-chcr-x2jhCGA-qvx9-3q6f-v465CGA-rg36-7rx9-mv47CGA-rm35-9r98-h6wfCGA-w22x-882f-3cr4CGA-wwmh-h3xg-hf8cCGA-x5j3-j56m-gr24CGA-x8vj-6553-9m2cCGA-xh6j-2f3c-5848CGA-xvqr-7xrc-qwjg
Deferred
Published: 06 Aug 2025, 20:41
Last modified:07 Aug 2025, 13:47

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
0.57% LOW
1% probability +0.47%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

06 Aug 2025, 20:41
Published
Vulnerability first disclosed
07 Aug 2025, 13:47
Last Modified
Vulnerability information updated

Description

Middleware causes a prohibitive amount of heap allocations when processing malicious preflight requests that include a Access-Control-Request-Headers (ACRH) header whose value contains many commas. This behavior can be abused by attackers to produce undue load on the middleware/server as an attempt to cause a denial of service.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.57% Percentile: 46%

Affected Systems

  • chainguardargo-cd-2.11

    < 2.11.4-r2

  • chainguardcortex

    < 1.17.1-r4

  • chainguardcortex-fips

    < 1.17.1-r6

  • chainguardfulcio

    < 1.4.5-r7

  • chainguardfulcio-fips

    < 1.4.5-r8

  • chainguardgrafana-mimir

    < 2.13.0-r1

  • chainguardprometheus-alertmanager

    < 0.27.0-r8

  • chainguardprometheus-alertmanager-fips

    < 0.27.0-r10

  • chainguardprometheus-alertmanager-fips-iamguarded-compat

    < 0.27.0-r10

  • chainguardprometheus-alertmanager-iamguarded-compat

    < 0.27.0-r8

  • chainguardrekor

    < 1.3.6-r8

  • chainguardrekor-backfill-index

    < 1.3.6-r8

  • chainguardrekor-cli

    < 1.3.6-r8

  • chainguardrekor-fips

    < 1.3.6-r9

  • chainguardrekor-fips-backfill-index

    < 1.3.6-r9

  • chainguardrekor-fips-cli

    < 1.3.6-r9

  • chainguardrekor-fips-server

    < 1.3.6-r9

  • chainguardrekor-server

    < 1.3.6-r8

  • chainguardtimestamp-authority

    < 1.2.2-r12

  • chainguardtimestamp-authority-cli

    < 1.2.2-r12

  • chainguardtimestamp-authority-fips

    < 1.2.2-r12

  • chainguardtimestamp-authority-fips-cli

    < 1.2.2-r12

  • chainguardtimestamp-authority-fips-server

    < 1.2.2-r12

  • chainguardtimestamp-authority-server

    < 1.2.2-r12

  • wolficortex

    < 1.17.1-r4

  • wolfifulcio

    < 1.4.5-r7

  • wolfigrafana-mimir

    < 2.13.0-r1

  • wolfiprometheus-alertmanager

    < 0.27.0-r8

  • wolfiprometheus-alertmanager-iamguarded-compat

    < 0.27.0-r8

  • wolfirekor

    < 1.3.6-r8

  • wolfirekor-backfill-index

    < 1.3.6-r8

  • wolfirekor-cli

    < 1.3.6-r8

  • wolfirekor-server

    < 1.3.6-r8

  • wolfitimestamp-authority

    < 1.2.2-r12

  • wolfitimestamp-authority-cli

    < 1.2.2-r12

  • wolfitimestamp-authority-server

    < 1.2.2-r12

  • github.com/rs/corsgithub.com/rs/cors

    ≥ 1.9.0, < 1.11.0

  • github.com/rscors

    ≥ 1.9.0, < 1.11.0

References (8)