VDB
CVE-2025-65409
CVE-2025-65409
PUBLISHED
CVSS 8.699999809265137 HIGH
A divide-by-zero in the encryption/decryption routines of GNU Recutils v1.9 allows attackers to cause a Denial of Service (DoS) via inputting an empty value as a password.
EPSS 0.36% · 27.0th percentile
Risk Scores
CVSS 4.0
8.699999809265137
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.36%
27.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| gnu | recutils | 1.9, 1.9 |
| n/a | n/a | n/a, n/a |
Timeline
- Dec 30, 2025 CVE Published
- Dec 30, 2025 PoC Published
- Dec 31, 2025 EPSS Score
- Jan 2, 2026 PoC Published
- Jan 4, 2026 EPSS Score
- Jan 8, 2026 EPSS Score
- Jan 12, 2026 EPSS Score
- Jan 16, 2026 EPSS Score
- Jan 20, 2026 EPSS Score
- Jan 24, 2026 EPSS Score
- Jan 28, 2026 EPSS Score
- Feb 1, 2026 EPSS Score
References
- http://ftp.gnu.org/gnu/recutils/ vendor
- https://www.gnu.org/software/recutils/ vendor
- https://nvd.nist.gov/vuln/detail/CVE-2025-65409 advisory
- https://github.com/MAXEUR5/Vulnerability_Disclosures/blob/main/2025/CVE-2025-65409.md url
- https://lists.gnu.org/archive/html/bug-recutils/2025-10/msg00004.html url
- https://www.gnu.org/software/recutils url
- http://ftp.gnu.org/gnu/recutils url