---
id: CVE-2025-22166
title: "This High severity DoS (Denial of Service) vulnerability was introduced in version 2.0 of Confluence Data Center.\r\n\r\nThis DoS (Denial of Service) vulnerability, with a CVSS Score of 8.3, allows an attacker to cause a resource to be unava…"
summary: "This High severity DoS (Denial of Service) vulnerability was introduced in version 2.0 of Confluence Data Center.\r\n\r\nThis DoS (Denial of Service) vulnerability, with a CVSS Score of 8.3, allows an attacker to cause a resource to be unava…"
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-405
vendor: atlassian
product: confluence_data_center
affected:
  - 'confluence_data_center >= 8.5.0, < 8.5.25'
  - 'confluence_data_center >= 9.2.0, < 9.2.7'
  - 'confluence_data_center >= 10.0.0, < 10.0.2'
  - 'confluence_server >= 8.5.0, < 8.5.25'
  - 'confluence_server >= 9.2.0, < 9.2.7'
  - 'confluence_server >= 10.0.0, < 10.0.2'
patched:
  - confluence_data_center 10.0.2
  - confluence_server 10.0.2
published: '2025-10-21'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-22166'
references:
  - url: 'https://confluence.atlassian.com/pages/viewpage.action?pageId=1652920034'
    label: security@atlassian.com
  - url: 'https://jira.atlassian.com/browse/CONFSERVER-100907'
    label: security@atlassian.com
tags:
  - nvd
epss: 0.00507
epssPercentile: 0.41023
ingestedAt: '2026-09-30T23:29:32.436Z'
---

## Overview

This High severity DoS (Denial of Service) vulnerability was introduced in version 2.0 of Confluence Data Center.

This DoS (Denial of Service) vulnerability, with a CVSS Score of 8.3, allows an attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services of a host connected to a network.

Atlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:
 Confluence Data Center and Server 8.5: Upgrade to a release greater than or equal to 8.5.25
 Confluence Data Center and Server 9.2: Upgrade to a release greater than or equal to 9.2.7
 Confluence Data Center and Server 10.0: Upgrade to a release greater than or equal to 10.0.2

See the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center from the download center ([https://www.atlassian.com/software/confluence/download-archives]).

This vulnerability was reported via our Atlassian (Internal) program.

## Affected

- `confluence_data_center >= 8.5.0, < 8.5.25`
- `confluence_data_center >= 9.2.0, < 9.2.7`
- `confluence_data_center >= 10.0.0, < 10.0.2`
- `confluence_server >= 8.5.0, < 8.5.25`
- `confluence_server >= 9.2.0, < 9.2.7`
- `confluence_server >= 10.0.0, < 10.0.2`

## Remediation

Upgrade past the affected range:

- `confluence_data_center 10.0.2`
- `confluence_server 10.0.2`
