DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CVE-2025-11579

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2025-11579

Severity

5.3

Medium

CVSS V3

Description

github.com/nwaples/rardecode versions <=2.1.1 fail to restrict the dictionary size when reading large RAR dictionary sizes, which allows an attacker to provide a specially crafted RAR file and cause Denial of Service via an Out Of Memory Crash.

References

Affected packages


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing