Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-59529

22
FAUCET Score

CVE-2025-59529 is a denial-of-service vulnerability affecting Avahi versions up to and including 0.9-rc2. The Avahi simple protocol server fails to enforce its documented client limit, allowing an unlimited number of connections. This flaw enables unprivileged local users to exhaust daemon memory and file descriptors, leading to a system-wide denial of service for mDNS/DNS-SD. Rated with a CVSS score of 5.5 (MEDIUM), the vulnerability has a local attack vector with low attack complexity, resulting in high availability impact. There is no known impact on confidentiality or integrity. As of the time of publication, there are no known patched versions, and no active exploitation or public exploit code has been identified. The vulnerability has received minimal community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.9CPE matchmatch criteria
cpe:2.3:a:avahi:avahi:*:*:*:*:*:*:*:*
0.9CPE matchmatch criteria
cpe:2.3:a:avahi:avahi:0.9:rc1:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.15%
Probability of exploitation in next 30 days
EPSS Percentile
5.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0015 is in the 31st percentile among its peer group of 15,938 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

github_advisorypatch availablevia nvd_reference
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: avahi
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: avahi
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: avahi
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: avahi
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: avahi
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: rhcos

Vendor Advisories (2)

redhatCVE-2025-59529Moderate

avahi: simple clients denial-of-service

Dec 11, 2025
microsoft2025-Dec/CVE-2025-59529Moderate

simple protocol server ignores accepts unlimited connections and logs failures without limit

Dec 9, 2025

References

openwall.com / lists/oss-security/2025/12/19/1
ExploitMailing List
github.com / avahi/avahi/pull/808
Issue TrackingPatch
github.com / avahi/avahi/security/advisories/GHSA-73wf-3xmj-x82q
ExploitVendor Advisory
zeropath.com / blog/avahi-simple-protocol-server-dos-cve-2025-59529
ExploitThird Party Advisory