{"id":"CVE-2020-25689","details":"A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in a loop, generating new connections which are not properly closed while not able to connect to domain-controller. This flaw allows an attacker to cause an Out of memory (OOM) issue, leading to a denial of service. The highest threat from this vulnerability is to system availability.","aliases":["BIT-wildfly-2020-25689","GHSA-97hp-6q9g-5cw2"],"modified":"2026-07-07T08:51:36.065650465Z","published":"2020-11-02T21:15:27.647Z","database_specific":{"unresolved_ranges":[{"extracted_events":[{"introduced":"6.0.0"},{"last_affected":"6.0.0"}],"source":"CPE_STRING","vendor_product":"redhat:fuse","cpes":["cpe:2.3:a:redhat:fuse:6.0.0:*:*:*:*:*:*:*"]},{"vendor_product":"redhat:jboss_data_grid","cpes":["cpe:2.3:a:redhat:jboss_data_grid:7.0.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"7.0.0"},{"last_affected":"7.0.0"}],"source":"CPE_STRING"},{"vendor_product":"redhat:jboss_enterprise_application_platform","cpes":["cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.0.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"7.0.0"},{"last_affected":"7.0.0"}],"source":"CPE_STRING"},{"extracted_events":[{"introduced":"7.0.0"},{"last_affected":"7.0.0"}],"source":"CPE_STRING","vendor_product":"redhat:jboss_fuse","cpes":["cpe:2.3:a:redhat:jboss_fuse:7.0.0:*:*:*:*:*:*:*"]},{"cpes":["cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"7.0"},{"last_affected":"7.0"}],"source":"CPE_STRING","vendor_product":"redhat:single_sign-on"}]},"references":[{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20201123-0006/"},{"type":"FIX","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-25689"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/wildfly/wildfly","events":[{"introduced":"0"},{"last_affected":"f3d5adb5a36fdc908d421537a35e8feffb3639be"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:redhat:wildfly:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"21.0.0"}]}}],"versions":["21.0.0.Final","21.0.0.Beta1","20.0.0.Final","20.0.0.Beta1","19.0.0.Beta2","19.0.0.Beta1","18.0.0.Final","18.0.0.Beta1","17.0.0.Final","17.0.0.Beta1","17.0.0.Alpha1","16.0.0.Final","16.0.0.Beta1","15.0.0.Final","15.0.0.Beta1","14.0.0.Final","14.0.0.Beta2","14.0.0.Beta1","13.0.0.Beta1","12.0.0.Final","12.0.0.CR1","12.0.0.Beta1","11.0.0.Final","11.0.0.CR1","10.0.0.Final","10.0.0.CR5","10.0.0.CR4","10.0.0.CR3","10.0.0.CR2","10.0.0.CR1","10.0.0.Beta2","10.0.0.Beta1","10.0.0.Alpha6","10.0.0.Alpha5","10.0.0.Alpha4","10.0.0.Alpha3","10.0.0.Alpha2","10.0.0.Alpha1","9.0.0.CR1","9.0.0.Beta2","9.0.0.Beta1","8.1.0.CR2","8.1.0.CR1","8.0.0.Final","8.0.0.CR1","8.0.0.Beta1","8.0.0.Alpha4","8.0.0.Alpha3","8.0.0.Alpha2","8.0.0.Alpha1","7.2.0.Final-prerelease1","7.2.0.Final","7.1.2.Final","7.1.2-prerelease","7.1.1.Final","7.1.0.Final","7.1.0.Final-prerelease2","7.1.0.Final-prerelease","7.1.0.CR1","7.1.0.Beta1","7.1.0.Alpha1","7.0.0.Final","7.0.0.Final-prerelease3","7.0.0.Final-prerelease2","7.0.0.Final-prerelease","7.0.0.CR1","7.0.0.Beta3","7.0.0.Beta2","7.0.0.Beta2-prerelease","7.0.0.Beta1-prerelease","7.0.0.Alpha1-final","7.0.0.Alpha1"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-25689.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}