Network Management

Why SolarWinds Observability Self-Hosted is not affected by CVE-2025-4748

This article explains why SolarWinds Observability Self-Hosted is not affected by CVE-2025-4748. SolarWinds Observability Self-Hosted does not use zip/unzip/extract functionality from Erlang’s stdlib.

First published date

7/8/2025 8:22 PM

Last published date

7/8/2025 8:22 PM

Overview

In 2025, the National Institute of Standards and Technology (NIST) published a security bulletin about CVE-2025-4748.

CVE-2025-4748 is associated with program files “lib/stdlib/src/zip.erl” and program routines zip:unzip/1, zip:unzip/2, zip:extract/1, zip:extract/2 unless the memory option is passed.

This issue affects OTP from OTP 17.0 until OTP 28.0.1, OTP 27.3.4.1, and OTP 26.2.5.13, corresponding to stdlib from 2.0 until 7.0.1, 6.2.2.1, and 5.2.3.4.

The vulnerability described in this CVE affects numerous software companies, but it does not impact SolarWinds Observability Self-Hosted.

Product section

Orion Platform

Cause

CVE-2025-4748

Resolution

This vulnerability affects only applications that meet all the prerequisites mentioned above.