CVE-2025-58369
fs2 is a compositional, streaming I/O library for Scala. Versions up to and including 2.5.12, 3.0.0-M1 through 3.12.2, and 3.13.0-M1 through 3.13.0-M6 are vulnerable to denial of service attacks though TLS sessions using fs2-io on the JVM using the fs2.io.net.tls package. When establishing a TLS session, if one side of the connection shuts down `write` while the peer side is awaiting more data to progress the TLS handshake, the peer side will spin loop on the socket read, fully utilizing a CPU. The CPU is consumed until the overall connection is closed, potentially shutting down a fs2-io powered server. This issue is fixed in versions 2.5.13, 3.12.1, and 3.13.0-M7.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- Puntuación base: 5.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.43%
- Percentil entre todas las CVEs puntuadas: 35
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-400
Referencias
- https://github.com/typelevel/fs2/commit/46e2dc3abf994dcf3d0b804b2ddb3c10c04d4976
- https://github.com/typelevel/fs2/commit/5c6c4c6c1ef330f7e6b53661ecc63d5f5ba8885c
- https://github.com/typelevel/fs2/commit/edf0c4f2e660360d1c1a8c5377ce32294de89238
- https://github.com/typelevel/fs2/issues/3590
- https://github.com/typelevel/fs2/releases/tag/v3.12.2
- https://github.com/typelevel/fs2/releases/tag/v3.13.0-M7
- https://github.com/typelevel/fs2/security/advisories/GHSA-rrw2-px9j-qffj
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-58369",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-58369",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-09-08T20:09:25.588603Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "typelevel",
"product": "fs2",
"versions": [
{
"status": "affected",
"version": ">= 3.0.0-M1, < 3.12.2"
},
{
"status": "affected",
"version": ">= 3.13.0-M1, < 3.13.0-M7"
},
{
"status": "affected",
"version": "< 2.5.13"
}
]
}
]
}
],
"published": "2025-09-05T22:15:34.883",
"references": [
{
"url": "https://github.com/typelevel/fs2/commit/46e2dc3abf994dcf3d0b804b2ddb3c10c04d4976",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/typelevel/fs2/commit/5c6c4c6c1ef330f7e6b53661ecc63d5f5ba8885c",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/typelevel/fs2/commit/edf0c4f2e660360d1c1a8c5377ce32294de89238",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/typelevel/fs2/issues/3590",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/typelevel/fs2/releases/tag/v3.12.2",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/typelevel/fs2/releases/tag/v3.13.0-M7",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/typelevel/fs2/security/advisories/GHSA-rrw2-px9j-qffj",
"source": "security-advisories@github.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-400"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "fs2 is a compositional, streaming I/O library for Scala. Versions up to and including 2.5.12, 3.0.0-M1 through 3.12.2, and 3.13.0-M1 through 3.13.0-M6 are vulnerable to denial of service attacks though TLS sessions using fs2-io on the JVM using the fs2.io.net.tls package. When establishing a TLS session, if one side of the connection shuts down `write` while the peer side is awaiting more data to progress the TLS handshake, the peer side will spin loop on the socket read, fully utilizing a CPU. The CPU is consumed until the overall connection is closed, potentially shutting down a fs2-io powered server. This issue is fixed in versions 2.5.13, 3.12.1, and 3.13.0-M7."
},
{
"lang": "es",
"value": "fs2 es una biblioteca de E/S composicional y de streaming para Scala. Las versiones hasta la 2.5.12 inclusive, de la 3.0.0-M1 a la 3.12.2, y de la 3.13.0-M1 a la 3.13.0-M6 son vulnerables a ataques de denegación de servicio a través de sesiones TLS usando fs2-io en la JVM utilizando el paquete fs2.io.net.tls. Al establecer una sesión TLS, si un lado de la conexión cierra la 'escritura' mientras el lado par está esperando más datos para avanzar el handshake TLS, el lado par entrará en un bucle de espera activa en la lectura del socket, utilizando completamente una CPU. La CPU es consumida hasta que la conexión general se cierra, potencialmente apagando un servidor impulsado por fs2-io. Este problema está solucionado en las versiones 2.5.13, 3.12.1 y 3.13.0-M7."
}
],
"lastModified": "2026-10-01T16:10:00.257",
"sourceIdentifier": "security-advisories@github.com"
}