[{"uuid":"GSA_kwCzR0hTQS00Mm1yLWpwd2gtbTlyds4ABHed","url":"https://github.com/advisories/GHSA-42mr-jpwh-m9rv","title":"Linkerd resource exhaustion vulnerability","description":"In Linkerd edge releases before edge-25.2.1, and Buoyant Enterprise for Linkerd releases 2.13.0–2.13.7, 2.14.0–2.14.10, 2.15.0–2.15.7, 2.16.0–2.16.4, and 2.17.0–2.17.1, resource exhaustion can occur for Linkerd proxy metrics.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2025-05-05T18:32:53.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2025-43915","https://docs.buoyant.io/security/advisories/2025-01","https://www.buoyant.io/resources","https://pkg.go.dev/vuln/GO-2025-3664","https://github.com/advisories/GHSA-42mr-jpwh-m9rv"],"source_kind":"github","identifiers":["GHSA-42mr-jpwh-m9rv","CVE-2025-43915"],"repository_url":null,"blast_radius":0.0,"created_at":"2025-05-06T01:08:11.593Z","updated_at":"2026-10-03T14:06:29.676Z","epss_percentage":0.0033,"epss_percentile":0.23819,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00Mm1yLWpwd2gtbTlyds4ABHed","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS00Mm1yLWpwd2gtbTlyds4ABHed","packages":[{"ecosystem":"go","package_name":"github.com/linkerd/linkerd2","versions":[{"first_patched_version":"0.0.0-20250212165942-faa3f617eef5","vulnerable_version_range":"\u003c 0.0.0-20250212165942-faa3f617eef5"}],"purl":"pkg:go/github.com%2Flinkerd%2Flinkerd2"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00Mm1yLWpwd2gtbTlyds4ABHed/related_packages","related_advisories":[]}]