FlawAtlas
Search the atlas
CVE-2025-48038 Moderate

Unverified File Handles can Cause Excessive Use of System Resources

## Summary Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh\_sftp modules) allows Excessive Allocation, Resource Leak Exposure. This vulnerability is associated with program files lib/ssh/src/ssh\_sftpd.erl. This issue affects OTP from OTP 17.0 before OTP 28.0.3, OTP 27.3.4.3 and OTP 26.2.5.15, corresponding to ssh from 3.0.1 before 5.3.3, 5.2.11.3 and 5.1.4.12. ## Workaround \* Disable sftp \* limiting number of max\_sessions allowed for sshd, so exploiting becomes more complicated ## Configuration The SFTP subsystem must be enabled on the SSH server and the SSH port must be reachable by the attacker. SFTP is enabled by default unless explicitly disabled by setting {subsystems, \[\]} in the SSH daemon configuration.

Exploit probability 0.4%
Published September 11, 2025
Required by Not available
Last source change July 30, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

79 explicit affected versions

Unknown Unknown

64 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2025-48038

Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Resource Leak Exposure. This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl. This issue affects OTP from OTP 17.0 before OTP 28.0.3, OTP 27.3.4.3 and OTP 26.2.5.15, corresponding to ssh from 3.0.1 before 5.3.3, 5.2.11.3 and 5.1.4.12.

View original source
Open Source Vulnerabilities EEF-CVE-2025-48038

## Summary Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh\_sftp modules) allows Excessive Allocation, Resource Leak Exposure. This vulnerability is associated with program files lib/ssh/src/ssh\_sftpd.erl. This issue affects OTP from OTP 17.0 before OTP 28.0.3, OTP 27.3.4.3 and OTP 26.2.5.15, corresponding to ssh from 3.0.1 before 5.3.3, 5.2.11.3 and 5.1.4.12. ## Workaround \* Disable sftp \* limiting number of max\_sessions allowed for sshd, so exploiting becomes more complicated ## Configuration The SFTP subsystem must be enabled on the SSH server and the SSH port must be reachable by the attacker. SFTP is enabled by default unless explicitly disabled by setting {subsystems, \[\]} in the SSH daemon configuration.

View original source

05 / REFERENCES

Further evidence