{"schema_version":"1.7.5","id":"CVE-2025-22869","published":"2025-02-26T08:14:24.997Z","modified":"2026-09-08T12:38:45.637216048Z","aliases":["GHSA-hcg3-q754-cr77","GO-2025-3487"],"related":["ALSA-2025:3210","ALSA-2025:3833","ALSA-2025:7462","ALSA-2025:7484","SUSE-RU-2025:02091-1","SUSE-RU-2025:02092-1","SUSE-RU-2025:02093-1","SUSE-SU-2025:03540-1","SUSE-SU-2025:03545-1","SUSE-SU-2025:0770-1","SUSE-SU-2025:0980-1","SUSE-SU-2025:1014-1","SUSE-SU-2025:1017-1","SUSE-SU-2025:1018-1","SUSE-SU-2025:1036-1","SUSE-SU-2025:1037-1","SUSE-SU-2025:1038-1","SUSE-SU-2025:1062-1","SUSE-SU-2025:1094-1","SUSE-SU-2025:1102-1","SUSE-SU-2025:1332-1","SUSE-SU-2025:1333-1","SUSE-SU-2025:20184-1","SUSE-SU-2025:20198-1","SUSE-SU-2025:20205-1","SUSE-SU-2025:20210-1","SUSE-SU-2025:20279-1","SUSE-SU-2025:20328-1","SUSE-SU-2025:20360-1","SUSE-SU-2025:20373-1","SUSE-SU-2025:20377-1","SUSE-SU-2025:20393-1","SUSE-SU-2025:20869-1","SUSE-SU-2026:0439-1","SUSE-SU-2026:0592-1","SUSE-SU-2026:0972-1","SUSE-SU-2026:1118-1","SUSE-SU-2026:1763-1","SUSE-SU-2026:20626-1","SUSE-SU-2026:20641-1","SUSE-SU-2026:21989-1","SUSE-SU-2026:22128-1","SUSE-SU-2026:22133-1","SUSE-SU-2026:22157-1","SUSE-SU-2026:22451-1","SUSE-SU-2026:22516-1","SUSE-SU-2026:22546-1","SUSE-SU-2026:22567-1","SUSE-SU-2026:22703-1","SUSE-SU-2026:22887-1","SUSE-SU-2026:2467-1","SUSE-SU-2026:2468-1","SUSE-SU-2026:2493-1","SUSE-SU-2026:2581-1","SUSE-SU-2026:2612-1","SUSE-SU-2026:2706-1","SUSE-SU-2026:2733-1","SUSE-SU-2026:3056-1","openSUSE-SU-2025:0094-1","openSUSE-SU-2025:14839-1","openSUSE-SU-2025:14843-1","openSUSE-SU-2025:14877-1","openSUSE-SU-2025:14881-1","openSUSE-SU-2025:14883-1","openSUSE-SU-2025:14887-1","openSUSE-SU-2025:14900-1","openSUSE-SU-2025:14909-1","openSUSE-SU-2025:14918-1","openSUSE-SU-2025:14919-1","openSUSE-SU-2025:14923-1","openSUSE-SU-2025:14930-1","openSUSE-SU-2025:14932-1","openSUSE-SU-2025:14940-1","openSUSE-SU-2025:14985-1","openSUSE-SU-2025:14988-1","openSUSE-SU-2025:14990-1","openSUSE-SU-2025:15054-1","openSUSE-SU-2025:15220-1","openSUSE-SU-2025:15304-1","openSUSE-SU-2025:15305-1","openSUSE-SU-2025:15389-1","openSUSE-SU-2025:15454-1","openSUSE-SU-2025:15487-1","openSUSE-SU-2025:15763-1","openSUSE-SU-2025:20143-1","openSUSE-SU-2025:20177-1","openSUSE-SU-2026:10230-1","openSUSE-SU-2026:10921-1","openSUSE-SU-2026:11126-1","openSUSE-SU-2026:11694-1","openSUSE-SU-2026:20192-1","openSUSE-SU-2026:20305-1","openSUSE-SU-2026:20581-1","openSUSE-SU-2026:20620-1","openSUSE-SU-2026:20730-1","openSUSE-SU-2026:20798-1","openSUSE-SU-2026:20893-1","openSUSE-SU-2026:20969-1","openSUSE-SU-2026:21079-1","openSUSE-SU-2026:21244-1","openSUSE-SU-2026:21247-1","openSUSE-SU-2026:21481-1","openSUSE-SU-2026:21603-1","openSUSE-SU-2026:21621-1"],"details":"SSH servers which implement file transfer protocols are vulnerable to a denial of service attack from clients which complete the key exchange slowly, or not at all, causing pending content to be read into memory, but never transmitted.","affected":[{"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-22869.json","unresolved_ranges":[{"events":[{"introduced":"0"},{"fixed":"0.35.0"}]}]}}],"references":[{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20250411-0010/"},{"type":"ADVISORY","url":"https://pkg.go.dev/vuln/GO-2025-3487"},{"type":"FIX","url":"https://go.dev/cl/652135"},{"type":"FIX","url":"https://go.dev/issue/71931"}],"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}