CVE 5.3 MEDIUM

DoS via Out Of Memory Crash_CVE-2025-11579

5.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Description

github.com/nwaples/rardecode versions <=2.1.1 fail to restrict the dictionary size when reading large RAR dictionary sizes, which allows an attacker to provide a specially crafted RAR file and cause Denial of Service via an Out Of Memory Crash.

Basic Information

ID CVE-2025-11579
Source Mattermost
Published Oct 10, 2025 at 11:15
Modified Oct 10, 2025 at 12:41

Affected Product

Vendor nwaples
Product rardecode
Version 2.0.1
Affected Versions nwaples rardecode 2.0.1

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.