CVE-2025-59975

Severity CVSS v4.0:
HIGH
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
09/10/2025
Last modified:
23/01/2026

Description

An Uncontrolled Resource Consumption vulnerability in the HTTP daemon (httpd) of Juniper Networks Junos Space allows an unauthenticated network-based attacker flooding the device with inbound API calls to consume all resources on the system, leading to a Denial of Service (DoS).<br /> <br /> After continuously flooding the system with inbound connection requests, all available file handles become consumed, blocking access to the system via SSH and the web user interface (WebUI), resulting in a management interface DoS. A manual reboot of the system is required to restore functionality.<br /> <br /> This issue affects Junos Space: <br /> * all versions before 22.2R1 Patch V3, <br /> * from 23.1 before 23.1R1 Patch V3.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:juniper:junos_space:*:*:*:*:*:*:*:* 22.2 (excluding)
cpe:2.3:a:juniper:junos_space:22.2:r1:*:*:*:*:*:*
cpe:2.3:a:juniper:junos_space:23.1:r1:*:*:*:*:*:*


References to Advisories, Solutions, and Tools