/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CVE-2025-11579

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2025-11579

Severity

5.3

Medium

CVSS V3

Description

github.com/nwaples/rardecode versions <=2.1.1 fail to restrict the dictionary size when reading large RAR dictionary sizes, which allows an attacker to provide a specially crafted RAR file and cause Denial of Service via an Out Of Memory Crash.

References

Affected packages


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing