CVE-2025-35435 - CVE House
Back to Database
Status published Medium CVE-2025-35435

CISA Thorium download stream divide by zero

Vulnerability Description

CISA Thorium accepts a stream split size of zero then divides by this value. A remote, authenticated attacker could cause the service to crash. Fixed in commit 89101a6.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-35435

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • , OpenAI Security Research

Affected Vendor

Affected Software

Thorium
Vulnerable Versions:
1.0.0, 89101a6

Timeline

Official Publish: September 17th, 2025
Last Modified: September 30th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Weaknesses (CWE)