CVE-2025-35435: exploitation status and patch state
CVE-2025-35435 · CVSS 4.3 MEDIUM · EPSS <1%
CISA Thorium accepts a stream split size of zero then divides by this value. A remote, authenticated attacker could cause the service to crash. Fixed in commit 89101a6.
Is CVE-2025-35435 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at <1%.
Public exploit code: none found in monitored sources.