AI description
CVE-2025-43537 refers to a vulnerability found in LibHTP, a security-aware parser for the HTTP protocol, affecting versions 0.5.50 and below. This vulnerability is characterized by a traffic-induced memory leak. The technical assessment indicates that this is a CWE-401 (Missing Release of Memory after Effective Lifetime) issue, where the application fails to properly release allocated memory after its effective lifetime. The memory leak can progressively consume system resources, potentially leading to resource starvation and a loss of visibility in the affected system. A patch has been released in version 0.5.51 to address the memory leak. As a workaround, users who cannot immediately update can set `suricata.yaml app-layer.protocols.http.libhtp.default-config.lzma-enabled` to false.
- Description
- A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2. Restoring a maliciously crafted backup file may lead to modification of protected system files.
- Source
- product-security@apple.com
- NVD status
- Modified
- Products
- ipados, iphone_os
CVSS 3.1
- Type
- Primary
- Base score
- 5.5
- Impact score
- 3.6
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
- Severity
- MEDIUM
- nvd@nist.gov
- NVD-CWE-noinfo
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE-22
- Hype score
- Not currently trending
CVE-2025-43537 A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5. Restoring a maliciously crafted backup file may lea… https://t.co/LbXww9Zdqw
@CVEnew
12 Feb 2026
475 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-43537 ⏳
@hichem_ifpdz
3 Dec 2025
5366 Impressions
2 Retweets
23 Likes
8 Bookmarks
8 Replies
1 Quote
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
"matchCriteriaId": "5DF4C0EE-C67C-4BA1-BB50-C51DEC72E486",
"versionEndExcluding": "18.7.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
"matchCriteriaId": "273784FD-F8F0-466D-AF6E-5511FF3781B7",
"versionEndExcluding": "18.7.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]