/
DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2025-25288

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2025-25288

CGA ID

CGA-mg8j-rfrx-fqh7

Severity

5.3

Medium

CVSS V3

Description

@octokit/plugin-paginate-rest is the Octokit plugin to paginate REST API endpoint responses. For versions starting in 1.0.0 and prior to 11.4.1 of the npm package @octokit/plugin-paginate-rest, when calling octokit.paginate.iterator(), a specially crafted octokit instance—particularly with a malicious link parameter in the headers section of the request—can trigger a ReDoS attack. Version 11.4.1 contains a fix for the issue.

References

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images