Incomplete Cleanup Affecting eclipse-threadx/netxduo package, versions [,6.4.3)


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.03% (6th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-ECLIPSETHREADXNETXDUO-9802329
  • published24 Apr 2025
  • disclosed6 Apr 2025
  • creditKelly Patterson

Introduced: 6 Apr 2025

NewCVE-2025-2260  (opens in a new tab)
CWE-459  (opens in a new tab)

How to fix?

Upgrade eclipse-threadx/netxduo to version 6.4.3 or higher.

Overview

Affected versions of this package are vulnerable to Incomplete Cleanup due to improper handling of error conditions in the HTTP server functionality. An attacker can cause the server to continuously return a 404 error for all subsequent file requests by sending specially crafted packets that exploit the failure to close a file when an error occurs.

Workaround

This vulnerability can be mitigated by disabling the PUT request support.

References

CVSS Base Scores

version 4.0
version 3.1