CVE-2025-43960

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-43960
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-43960.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-43960
Aliases
Downstream
Published
2025-08-25T14:15:30Z
Modified
2025-08-31T08:49:49.519926Z
Summary
[none]
Details

Adminer 4.8.1, when using Monolog for logging, allows a Denial of Service (memory consumption) via a crafted serialized payload (e.g., using s:1000000000), leading to a PHP Object Injection issue. Remote, unauthenticated attackers can trigger this by sending a malicious serialized object, which forces excessive memory usage, rendering Adminer’s interface unresponsive and causing a server-level DoS. While the server may recover after several minutes, multiple simultaneous requests can cause a complete crash requiring manual intervention.

References

Affected packages

Debian:11 / adminer

Package

Name
adminer
Purl
pkg:deb/debian/adminer?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*

4.7.9-2
4.8.1-1
4.8.1-2
4.8.1-4

5.*

5.1.0-1
5.2.1+dfsg-1
5.3.0+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / adminer

Package

Name
adminer
Purl
pkg:deb/debian/adminer?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*

4.8.1-1
4.8.1-2
4.8.1-4

5.*

5.1.0-1
5.2.1+dfsg-1
5.3.0+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / adminer

Package

Name
adminer
Purl
pkg:deb/debian/adminer?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*

5.2.1+dfsg-1
5.3.0+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:14 / adminer

Package

Name
adminer
Purl
pkg:deb/debian/adminer?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*

5.2.1+dfsg-1
5.3.0+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}