CVE-2025-52494 is a denial-of-service vulnerability affecting Adacore Ada Web Server (AWS) versions before 25.2. An attacker can exploit this by sending malformed TLS ClientHello messages during HTTPS connection initialization, causing the server to indefinitely block worker threads. This can exhaust all available threads, preventing legitimate requests from being processed. The vulnerability has a CVSS score of 7.5 (HIGH), indicating a significant impact on availability with low attack complexity and no user interaction required. While the EPSS score is very low, suggesting a low probability of exploitation, the FAUCET Risk Score is 72/100, highlighting its potential severity. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) or community discussion has been identified. This suggests that while the vulnerability is serious, it has not yet garnered significant attention from threat actors or the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 26.0CPE matchmatch criteria | cpe:2.3:a:adacore:ada_web_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.