CVE-2025-20359

Source
https://cve.org/CVERecord?id=CVE-2025-20359
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-20359.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-20359
Published
2025-10-15T17:15:49Z
Modified
2026-09-19T08:16:04Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H CVSS Calculator
Summary
[none]
Details

Multiple Cisco products are affected by a vulnerability in the Snort 3 HTTP Decoder that could allow an unauthenticated, remote attacker to cause the disclosure of possible sensitive data or cause the Snort 3 Detection Engine to crash.

This vulnerability is due to an error in the logic of buffer handling when the MIME fields of the HTTP header are parsed. This can result in a buffer under-read. An attacker could exploit this vulnerability by sending crafted HTTP packets through an established connection that is parsed by Snort 3. A successful exploit could allow the attacker to induce one of two possible outcomes: the unexpected restarting of the Snort 3 Detection Engine, which could cause a denial of service (DoS) condition, or information disclosure of sensitive information in the Snort 3 data stream. Due to the under-read condition, it is possible that sensitive information that is not valid connection data could be returned.

References

Affected packages

Git / github.com/snort3/snort3

Affected ranges

Type
GIT
Repo
https://github.com/snort3/snort3
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:cisco:snort:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "3.0.0-233"
        },
        {
            "fixed": "3.9.3.0"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

3.*
3.0.0-233
3.0.0-239
3.0.0-240
3.0.0-241
3.0.0-242
3.0.0-243
3.0.0-244
3.0.0-245
3.0.0-246
3.0.0-247
3.0.0-248
3.0.0-249
3.0.0-250
3.0.0-251
3.0.0-252
3.0.0-253
3.0.0-254
3.0.0-255
3.0.0-256
3.0.0-257
3.0.0-258
3.0.0-259
3.0.0-260
3.0.0-261
3.0.0-262
3.0.0-263
3.0.0-264
3.0.0-265
3.0.0-266
3.0.0-267
3.0.0-268
3.0.0-269
3.0.0-270
3.0.0_253
3.0.1-1
3.0.1-2
3.0.1-3
3.0.1-4
3.0.1-5
3.0.2-1
3.0.2-2
3.0.2-3
3.0.2-4
3.0.2-5
3.0.2-6
3.0.3-1
3.0.3-2
3.0.3-3
3.0.3-4
3.0.3-5
3.0.3-6
3.1.0.0
3.1.1.0
3.1.10.0
3.1.11.0
3.1.12.0
3.1.13.0
3.1.14.0
3.1.15.0
3.1.16.0
3.1.17.0
3.1.18.0
3.1.19.0
3.1.2.0
3.1.20.0
3.1.21.0
3.1.22.0
3.1.23.0
3.1.24.0
3.1.25.0
3.1.26.0
3.1.27.0
3.1.28.0
3.1.29.0
3.1.3.0
3.1.30.0
3.1.31.0
3.1.32.0
3.1.33.0
3.1.34.0
3.1.35.0
3.1.36.0
3.1.37.0
3.1.38.0
3.1.39.0
3.1.4.0
3.1.40.0
3.1.41.0
3.1.42.0
3.1.43.0
3.1.45.0
3.1.47.0
3.1.48.0
3.1.49.0
3.1.5.0
3.1.50.0
3.1.51.0
3.1.52.0
3.1.53.0
3.1.55.0
3.1.56.0
3.1.57.0
3.1.58.0
3.1.59.0
3.1.6.0
3.1.60.0
3.1.61.0
3.1.62.0
3.1.63.0
3.1.64.0
3.1.65.0
3.1.66.0
3.1.67.0
3.1.69.0
3.1.7.0
3.1.70.0
3.1.71.0
3.1.72.0
3.1.73.0
3.1.74.0
3.1.75.0
3.1.76.0
3.1.77.0
3.1.78.0
3.1.79.0
3.1.8.0
3.1.81.0
3.1.82.0
3.1.83.0
3.1.84.0
3.1.9.0
3.2.1.0
3.2.2.0
3.3.0.0
3.3.1.0
3.3.2.0
3.3.3.0
3.3.4.0
3.3.5.0
3.3.7.0
3.4.0.0
3.5.0.0
3.5.1.0
3.5.2.0
3.6.0.0
3.6.1.0
3.6.2.0
3.6.3.0
3.7.0.0
3.7.1.0
3.7.2.0
3.7.3.0
3.7.4.0
3.8.1.0
3.9.0.0
3.9.1.0
3.9.2.0
Other
BUILD_233
BUILD_239
BUILD_240
BUILD_241
BUILD_242
BUILD_243
BUILD_247
BUILD_248

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-20359.json"