In NextX Duo before 6.4.4, in the HTTP client module, the network support code for Eclipse Foundation ThreadX, the parsing of HTTP header fields was missing bounds verification. A crafted server response could cause undefined behavior.
Metrics
Affected Vendors & Products
References
History
Fri, 17 Oct 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In NextX Duo before 6.4.4, in the HTTP client module, the network support code for Eclipse Foundation ThreadX, the parsing of HTTP header fields was missing bounds verification. A crafted server response could cause undefined behavior. | |
Title | Web http client: Unchecked Server-Side Malicious Packet Issue | |
Weaknesses | CWE-125 CWE-1286 |
|
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: eclipse
Published:
Updated: 2025-10-17T14:22:28.880Z
Reserved: 2025-08-06T18:32:14.666Z
Link: CVE-2025-55085

No data.

Status : Received
Published: 2025-10-17T15:15:38.907
Modified: 2025-10-17T15:15:38.907
Link: CVE-2025-55085

No data.

No data.