Skip to main content

Threats Tagged 'cve-2025-59089'

View all threats tagged with 'cve-2025-59089'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2025-59089

Threats Tagged 'cve-2025-59089'

Click on any threat for detailed analysis and mitigation recommendations

Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. Security Fix(es): * python-kdcproxy: Unauthenticated SSRF via Realm?Controlled DNS SRV (CVE-2025-59088) * python-kdcproxy: Remote DoS via unbounded TCP upstream buffering (CVE-2025-59089) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion
0

Red Hat Identity Management (IdM) has security vulnerabilities in the python-kdcproxy component, including an unauthenticated Server-Side Request Forgery (SSRF) via realm-controlled DNS SRV records (CVE-2025-59088) and a remote Denial of Service (DoS) via unbounded TCP upstream buffering (CVE-2025-59089). These issues affect Red Hat Enterprise Linux 8.6 variants. Red Hat has issued an important security update to address these vulnerabilities.

Join the discussion
0

Red Hat Identity Management (IdM) has security vulnerabilities in the python-kdcproxy component, including an unauthenticated Server-Side Request Forgery (SSRF) via realm-controlled DNS SRV records (CVE-2025-59088) and a remote Denial of Service (DoS) via unbounded TCP upstream buffering (CVE-2025-59089). These issues affect Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and Telecommunications Update Service. Red Hat has released an important security update to address these vulnerabilities.

Join the discussion
0

Red Hat Identity Management (IdM) for Red Hat Enterprise Linux 8.2 contains two security vulnerabilities in the python-kdcproxy component. The first is an unauthenticated Server-Side Request Forgery (SSRF) via realm-controlled DNS SRV records (CVE-2025-59088). The second is a remote Denial of Service (DoS) caused by unbounded TCP upstream buffering (CVE-2025-59089). These issues have been addressed in an important security update released by Red Hat. The update is available for Red Hat Enterprise Linux Server AUS 8.2 x86_64. No CVSS scores are provided, but the vendor rates the impact as important. No known exploits in the wild have been reported.

Join the discussion

Two security vulnerabilities have been identified in the python-kdcproxy component of Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions. The first is an unauthenticated Server-Side Request Forgery (SSRF) vulnerability via realm-controlled DNS SRV records (CVE-2025-59088). The second is a remote Denial of Service (DoS) vulnerability caused by unbounded TCP upstream buffering (CVE-2025-59089). Red Hat has released an important security update addressing these issues for multiple architectures including x86_64, ppc64le, aarch64, and s390x. Users of affected Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions should apply the update to mitigate these vulnerabilities.

Join the discussion

Two security vulnerabilities have been identified in the python-kdcproxy component of Red Hat Enterprise Linux 9.4 Extended Update Support. The first is an unauthenticated Server-Side Request Forgery (SSRF) vulnerability via realm-controlled DNS SRV records (CVE-2025-59088). The second is a remote denial-of-service (DoS) vulnerability caused by unbounded TCP upstream buffering (CVE-2025-59089). Red Hat has released an important security update addressing these issues for multiple architectures and variants of RHEL 9.4.

Join the discussion

Two security vulnerabilities were identified in the python-kdcproxy component of Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions. The first is an unauthenticated Server-Side Request Forgery (SSRF) vulnerability via realm-controlled DNS SRV records (CVE-2025-59088). The second is a remote Denial of Service (DoS) vulnerability caused by unbounded TCP upstream buffering (CVE-2025-59089). Red Hat has released an important security update addressing these issues for multiple architectures and lifecycle variants of RHEL 9.2.

Join the discussion
0

Red Hat Identity Management (IdM) for Red Hat Enterprise Linux 8 has security vulnerabilities in the python-kdcproxy component. These include an unauthenticated Server-Side Request Forgery (SSRF) via realm-controlled DNS SRV records (CVE-2025-59088) and a remote denial of service (DoS) caused by unbounded TCP upstream buffering (CVE-2025-59089). Red Hat has released an important security update addressing these issues.

Join the discussion

If an attacker causes kdcproxy to connect to an attacker-controlled KDC server (e.g. through server-side request forgery), they can exploit the fact that kdcproxy does not enforce bounds on TCP response length to conduct a denial-of-service attack. While receiving the KDC's response, kdcproxy copies the entire buffered stream into a new buffer on each recv() call, even when the transfer is incomplete, causing excessive memory allocation and CPU usage. Additionally, kdcproxy accepts incoming response chunks as long as the received data length is not exactly equal to the length indicated in the response header, even when individual chunks or the total buffer exceed the maximum length of a Kerberos message. This allows an attacker to send unbounded data until the connection timeout is reached (approximately 12 seconds), exhausting server memory or CPU resources. Multiple concurrent requests can cause accept queue overflow, denying service to legitimate clients.

Join the discussion

Two security vulnerabilities were identified in python-kdcproxy, a Python module used in Red Hat Enterprise Linux 9.6 Extended Update Support. The first vulnerability (CVE-2025-59088) is an unauthenticated Server-Side Request Forgery (SSRF) via realm-controlled DNS SRV records. The second (CVE-2025-59089) is a remote denial-of-service (DoS) caused by unbounded TCP upstream buffering. Red Hat has issued an important security update addressing these issues for multiple architectures and variants of RHEL 9.6.

Join the discussion

Showing 1 to 10 of 13 results

Filters:Tag: cve-2025-59089
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses