{"id":"CVE-2025-61908","summary":"Icinga 2 Denial of Service (DoS) By Dereferencing Invalid Reference","details":"Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14.7, and 2.13.13, when creating an invalid reference, such as a reference to null, dereferencing results in a segmentation fault. This can be used by any API user with access to an API endpoint that allows specifying a filter expression to crash the Icinga 2 daemon. A fix is included in the following Icinga 2 versions: 2.15.1, 2.14.7, and 2.13.13.","aliases":["GHSA-v9jg-xqhj-f43g"],"modified":"2026-08-12T03:51:34.392506100Z","published":"2025-10-16T17:16:58.165Z","related":["openSUSE-SU-2025:15644-1"],"database_specific":{"cwe_ids":["CWE-476"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/61xxx/CVE-2025-61908.json","cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/61xxx/CVE-2025-61908.json"},{"type":"ADVISORY","url":"https://github.com/Icinga/icinga2/security/advisories/GHSA-v9jg-xqhj-f43g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-61908"},{"type":"FIX","url":"https://github.com/Icinga/icinga2/pull/6521"},{"type":"ARTICLE","url":"https://icinga.com/blog/releasing-icinga-2-v2-15-1-2-14-7-and-2-13-13-and-icinga-db-web-v1-2-3-and-1-1-4"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/icinga/icinga2","events":[{"introduced":"b86c918d4d7bb5415375babc595b279a7452732d"},{"fixed":"d1d9403eac58cd2e582e6a4e95a0661f3f81d814"},{"introduced":"0d5802937ba274fd3b9e13a48c4638cc104ad577"},{"fixed":"67072d3c5b50026dba702b4031eb4f22ea65ff3b"},{"introduced":"f87948081fc2386fc7a30eb12ab01cb907dbe3fb"},{"fixed":"19e9b0042a11a7195ee4b6d2332b2319699d6b60"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:icinga:icinga:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.10.0"},{"fixed":"2.13.13"},{"introduced":"2.14.0"},{"fixed":"2.14.7"},{"introduced":"2.15.0"},{"fixed":"2.15.1"}]}}],"versions":["v2.14.5","v2.15.0","v2.13.11","v2.14.4","v2.13.9","v2.14.2","v2.14.1","v2.14.0","v2.13.8","v2.13.5","v2.13.7","v2.13.6","v2.13.3","v2.13.4","v2.13.2","v2.13.0","v2.12.0","v2.11.0","v2.12.0-rc1","v2.11.0-rc1","v2.10.1","v2.10.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-61908.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}