We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-22854

Possible thread exhaustion from processing http responses in PingFederate Google Adapter



Description

Improper handling of non-200 http responses in the PingFederate Google Adapter leads to thread exhaustion under normal usage conditions.

Reserved 2025-01-13 | Published 2025-06-15 | Updated 2025-06-15 | Assigner Ping Identity


MEDIUM: 6.9CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/S:P/AU:Y/R:A/RE:M/U:Red

Problem types

CWE-394 Unexpected Status Code or Return Value

Product status

Default status
unaffected

1.0.1 before 1.5.2
affected

References

www.pingidentity.com/...esources/downloads/pingfederate.html patch

docs.pingidentity.com/...on_kit/pf_google_cic_changelog.html release-notes

cve.org (CVE-2025-22854)

nvd.nist.gov (CVE-2025-22854)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-22854

Support options

Helpdesk Chat, Email, Knowledgebase