216.73.217.22

CVE-2025-22166

· Published 21/10/2025 16:15 · Modified 21/10/2025 19:31

Labels: CVE-2025-22166 2025-10-21CVE-2025-22166CWE-405[email protected]

Essential information

Published
21/10/2025 16:15
Modified
21/10/2025 19:31
Author
Creator
CVSS
8.3 HIGH (v3) 8.3 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

This High severity DoS (Denial of Service) vulnerability was introduced in version 2.0 of Confluence Data Center. This DoS (Denial of Service) vulnerability, with a CVSS Score of 8.3, allows an attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services of a host connected to a network. Atlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Confluence Data Center and Server 8.5: Upgrade to a release greater than or equal to 8.5.25 Confluence Data Center and Server 9.2: Upgrade to a release greater than or equal to 9.2.7 Confluence Data Center and Server 10.0: Upgrade to a release greater than or equal to 10.0.2 See the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center from the download center ([https://www.atlassian.com/software/confluence/download-archives]). This vulnerability was reported via our Atlassian (Internal) program.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
atlassian / confluence cpe:2.3:a:atlassian:confluence:8.5.25:*:*:*:*:*:*:*
atlassian / confluence cpe:2.3:a:atlassian:confluence:9.2.7:*:*:*:*:*:*:*
atlassian / confluence cpe:2.3:a:atlassian:confluence:10.0.2:*:*:*:*:*:*:*

References