Loading HuntDB...

CVE-2025-46807

UNKNOWN
Published 2025-06-02T11:29:13.603Z
Actions:

Expert Analysis

Professional remediation guidance

Get tailored security recommendations from our analyst team for CVE-2025-46807. We'll provide specific mitigation strategies based on your environment and risk profile.

No CVSS data available

Description

A Allocation of Resources Without Limits or Throttling vulnerability in sslh allows attackers to easily exhaust the file descriptors in sslh and deny legitimate users service.This issue affects sslh before 2.2.4.

Available Exploits

No exploits available for this CVE.

Related News

sslh: Remote Denial-of-Service Vulnerabilities (CVE-2025-46807, CVE-2025-46806)

Posted by Matthias Gerstner on Jun 13Hello list, this is a review report about remote Denial-of-Service vulnerabilities in sslh. We also offer a rendered HTML version of this report on our blog [1]. Please find the full details below. 1) Introduction ======…

Seclists.org 2025-06-13 14:32

Affected Products

EU Vulnerability Database

Monitored by ENISA for EU cybersecurity

EU Coordination

EU Coordinated

Exploitation Status

No Known Exploitation

ENISA Analysis

A Allocation of Resources Without Limits or Throttling vulnerability in sslh allows attackers to easily exhaust the file descriptors in sslh and deny legitimate users service.This issue affects sslh before 2.2.4.

Affected Products (ENISA)

https://github.com/yrutschle/sslh/releases/tag/v2.2.4
sslh

ENISA Scoring

CVSS Score (4.0)

8.7
/10
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

EPSS Score

0.060
probability

Data provided by ENISA EU Vulnerability Database. Last updated: June 2, 2025

GitHub Security Advisories

Community-driven vulnerability intelligence from GitHub

⚠ Unreviewed HIGH

GHSA-5pmj-5f4j-wp6g

Advisory Details

A Allocation of Resources Without Limits or Throttling vulnerability in sslh allows attackers to easily exhaust the file descriptors in sslh and deny legitimate users service.This issue affects sslh before 2.2.4.

CVSS Scoring

CVSS Score

7.5

CVSS Vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Advisory provided by GitHub Security Advisory Database. Published: June 2, 2025, Modified: June 2, 2025

Social Media Intelligence

Real-time discussions and threat intelligence from social platforms

1 post
Reddit 2 weeks ago
Dark-Marc

New sslh Vulnerabilities Enable Remote Denial-of-Service Attacks **Two critical vulnerabilities in the popular sslh protocol demultiplexer could allow attackers to trigger remote DoS attacks and disrupt service availability.** **Key Points:** - CVE-2025-46807 allows file descriptor exhaustion leading to service crashes. - CVE-2025-46806 causes crashes due to misaligned memory access within …

Also mentions: CVE-2025-46806

References

Published: 2025-06-02T11:29:13.603Z
Last Modified: 2025-06-02T16:30:22.046Z
Copied to clipboard!