spdlog pattern_formatter-inl.h scoped_padder resource consumption

CVE Details

Basic Information

Title spdlog pattern_formatter-inl.h scoped_padder resource consumption
Type cve
Published 2025-06-16T21:31:06.961Z
Last Seen

Product Information

Vendor n/a
Product spdlog
Version 1.15.0

CVSS Information

Base Score 4.8 (MEDIUM)
Attack Vector CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
Confidentiality Impact
Integrity Impact
Availability Impact

AI Analysis

AI Description The spdlog library up to version 1.15.1 is vulnerable to a resource consumption issue in the scoped_padder function of the pattern_formatter-inl.h file. This vulnerability can be exploited locally to consume excessive resources, potentially leading to denial of service. The issue has been patched in version 1.15.2.
AI Severity Medium
Vendor spdlog Community
Product spdlog
Affected Version 1.15.0, 1.15.1

Affected Products

  • n/a spdlog 1.15.0
  • n/a spdlog 1.15.1

Additional Information

CVE List
CWE List CWE-400, CWE-404
Bulletin Family

Description

A vulnerability, which was classified as problematic, was found in spdlog up to 1.15.1. This affects the function scoped_padder in the library include/spdlog/pattern_formatter-inl.h. The manipulation leads to resource consumption. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. Upgrading to version 1.15.2 is able to address this issue. The identifier of the patch is 10320184df1eb4638e253a34b1eb44ce78954094. It is recommended to upgrade the affected component.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.