{"id":"CVE-2025-43915","aliases":["GHSA-42mr-jpwh-m9rv","GO-2025-3664"],"url":"https://o3.security/vulnerability/CVE-2025-43915","summary":"Linkerd resource exhaustion vulnerability","details":"In Linkerd edge releases before edge-25.2.1, and Buoyant Enterprise for Linkerd releases 2.13.0–2.13.7, 2.14.0–2.14.10, 2.15.0–2.15.7, 2.16.0–2.16.4, and 2.17.0–2.17.1, resource exhaustion can occur for Linkerd proxy metrics.","published":"2025-05-05T00:00:00Z","modified":"2026-07-15T01:49:13.932848824Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/linkerd/linkerd2","fixedVersion":"0.0.0-20250212165942-faa3f617eef5"}],"fix":null,"references":[{"type":"WEB","url":"https://www.buoyant.io/resources"},{"type":"ADVISORY","url":"https://docs.buoyant.io/security/advisories/2025-01/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/43xxx/CVE-2025-43915.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-43915"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:13.932848824Z"}}