← back
CVE-2025-12383

Race Condition allows Bypass of Trust Restrictions

CVSS 9.4 CRITICALEPSS 0.3%CWE-362
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.4EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
18 Nov 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In Eclipse Jersey versions 2.45, 3.0.16, 3.1.9 a race condition can cause ignoring of critical SSL configurations - such as mutual authentication, custom key/trust stores, and other security settings. This issue may result in SSLHandshakeException under normal circumstances, but under certain conditions, it could lead to unauthorized trust in insecure servers (see PoC)
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →