{"id":"CVE-2025-20359","details":"Multiple Cisco products are affected by a vulnerability in the Snort 3 HTTP Decoder that could allow an unauthenticated, remote attacker to cause the disclosure of possible sensitive data or cause the Snort 3 Detection Engine to crash.\r\n\r\nThis vulnerability is due to an error in the logic of buffer handling when the MIME fields of the HTTP header are parsed. This can result in a buffer under-read. An attacker could exploit this vulnerability by sending crafted HTTP packets through an established connection that is parsed by Snort 3. A successful exploit could allow the attacker to induce one of two possible outcomes: the unexpected restarting of the Snort 3 Detection Engine, which could cause a denial of service (DoS) condition, or information disclosure of sensitive information in the Snort 3 data stream. Due to the under-read condition, it is possible that sensitive information that is not valid connection data could be returned.","modified":"2026-09-19T08:16:04.713341Z","published":"2025-10-15T17:15:49.230Z","references":[{"type":"ADVISORY","url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snort3-mime-vulns-tTL8PgVH"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/snort3/snort3","events":[{"introduced":"7ae50f4be245efd469dee2ce2855b6235b07aa42"},{"fixed":"9a75c88920274d37dfa4bb28b10189b706e85354"}],"database_specific":{"cpe":"cpe:2.3:a:cisco:snort:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"3.0.0-233"},{"fixed":"3.9.3.0"}],"source":"CPE_RANGE"}}],"versions":["3.9.2.0","3.9.1.0","3.9.0.0","3.8.1.0","3.7.4.0","3.7.3.0","3.7.2.0","3.7.1.0","3.7.0.0","3.6.3.0","3.6.2.0","3.6.1.0","3.6.0.0","3.5.2.0","3.5.1.0","3.5.0.0","3.4.0.0","3.3.7.0","3.3.5.0","3.3.4.0","3.3.3.0","3.3.2.0","3.3.1.0","3.3.0.0","3.2.2.0","3.2.1.0","3.1.84.0","3.1.83.0","3.1.82.0","3.1.81.0","3.1.79.0","3.1.78.0","3.1.77.0","3.1.76.0","3.1.75.0","3.1.74.0","3.1.73.0","3.1.72.0","3.1.71.0","3.1.70.0","3.1.69.0","3.1.67.0","3.1.66.0","3.1.65.0","3.1.64.0","3.1.63.0","3.1.62.0","3.1.61.0","3.1.60.0","3.1.59.0","3.1.58.0","3.1.57.0","3.1.56.0","3.1.55.0","3.1.53.0","3.1.52.0","3.1.51.0","3.1.50.0","3.1.49.0","3.1.48.0","3.1.47.0","3.1.45.0","3.1.43.0","3.1.42.0","3.1.41.0","3.1.40.0","3.1.39.0","3.1.38.0","3.1.37.0","3.1.36.0","3.1.35.0","3.1.34.0","3.1.33.0","3.1.32.0","3.1.31.0","3.1.30.0","3.1.29.0","3.1.28.0","3.1.27.0","3.1.26.0","3.1.25.0","3.1.24.0","3.1.23.0","3.1.22.0","3.1.21.0","3.1.20.0","3.1.19.0","3.1.18.0","3.1.17.0","3.1.16.0","3.1.15.0","3.1.14.0","3.1.13.0","3.1.12.0","3.1.11.0","3.1.10.0","3.1.9.0","3.1.8.0","3.1.7.0","3.1.6.0","3.1.5.0","3.1.4.0","3.1.3.0","3.1.2.0","3.1.1.0","3.1.0.0","3.0.3-6","3.0.3-5","3.0.3-4","3.0.3-3","3.0.3-2","3.0.3-1","3.0.2-6","3.0.2-5","3.0.2-4","3.0.2-3","3.0.2-2","3.0.2-1","3.0.1-5","3.0.1-4","3.0.1-3","3.0.1-2","3.0.1-1","3.0.0-270","3.0.0-269","3.0.0-268","3.0.0-267","3.0.0-266","3.0.0-265","3.0.0-264","3.0.0-263","3.0.0-262","3.0.0-261","3.0.0-260","3.0.0-259","3.0.0-258","3.0.0-257","3.0.0-256","3.0.0-255","3.0.0-254","3.0.0_253","3.0.0-253","3.0.0-252","3.0.0-251","3.0.0-250","3.0.0-249","BUILD_248","3.0.0-248","BUILD_247","3.0.0-247","3.0.0-246","3.0.0-245","3.0.0-244","BUILD_243","3.0.0-243","BUILD_242","3.0.0-242","BUILD_241","3.0.0-241","BUILD_240","3.0.0-240","BUILD_239","3.0.0-239","BUILD_233","3.0.0-233"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-20359.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"}]}