CVE-2025-43915: Linkerd Buoyant
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
In Linkerd edge releases before edge-25.2.1, and Buoyant Enterprise for Linkerd releases 2.13.0–2.13.7, 2.14.0–2.14.10, 2.15.0–2.15.7, 2.16.0–2.16.4, and 2.17.0–2.17.1, resource exhaustion can occur for Linkerd proxy metrics.
Affected products
- Linkerd Buoyant: from 2.13.0, up to and including 2.13.7; from 2.14.0, up to and including 2.14.10; from 2.15.0, up to and including 2.15.7; from 2.16.0, before 2.16.5 (fixed in 2.16.5); from 2.17.0, before 2.17.2 (fixed in 2.17.2)
- Linkerd Linkerd: before 25.2.1 (fixed in 25.2.1)
Published 2025-05-05. Last modified 2026-06-17.