CVE-2025-25288
Last modified
CVE-2025-25288 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. @octokit/plugin-paginate-rest is the Octokit plugin to paginate REST API endpoint responses. For versions starting in 1.0.0 and prior to 11.4.1 of the npm package `@octokit/plugin-paginate-rest`, when calling `octokit.paginate.iterator()`, a specially crafted `octokit` instance—particularly with a malicious `link` parameter in the `headers` section of the `request`—can trigger a ReDoS attack. EPSS estimates a 0.58% chance of exploitation in the next 30 days.
Description
@octokit/plugin-paginate-rest is the Octokit plugin to paginate REST API endpoint responses. For versions starting in 1.0.0 and prior to 11.4.1 of the npm package `@octokit/plugin-paginate-rest`, when calling `octokit.paginate.iterator()`, a specially crafted `octokit` instance—particularly with a malicious `link` parameter in the `headers` section of the `request`—can trigger a ReDoS attack. Version 11.4.1 contains a fix for the issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-25288?
How severe is CVE-2025-25288?
How do I fix CVE-2025-25288?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-25282RAGFlow is an open-source RAG (Retrieval-Augmented Generatio…8.1
- CVE-2025-25283parse-duraton is software that allows users to convert a hum…7.5
- CVE-2025-25284The ZOO-Project is an open source processing platform, relea…8.7
- CVE-2025-25285@octokit/endpoint turns REST API endpoints into generic requ…5.3
- CVE-2025-25286Crayfish is a collection of Islandora 8 microservices, one o…9.8
- CVE-2025-25287Lakeus is a simple skin made for MediaWiki. Starting in vers…4.7
- CVE-2025-25289@octokit/request-error is an error class for Octokit request…5.3
- CVE-2025-2529Applications using affected versions of Ehcache 3.x can expe…3.7
- CVE-2025-25290@octokit/request sends parameterized requests to GitHub’s AP…5.3
- CVE-2025-25291ruby-saml provides security assertion markup language (SAML)…9.8
- CVE-2025-25292ruby-saml provides security assertion markup language (SAML)…9.8
- CVE-2025-25293ruby-saml provides security assertion markup language (SAML)…7.5
Are you affected by CVE-2025-25288?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
