We found results for “”
CVE-2025-11579
Good to know:
Date: October 10, 2025
github.com/nwaples/rardecode versions <=2.1.1 fail to restrict the dictionary size when reading large RAR dictionary sizes, which allows an attacker to provide a specially crafted RAR file and cause Denial of Service via an Out Of Memory Crash.
Severity Score
Related Resources (6)
Severity Score
Weakness Type (CWE)
Memory Allocation with Excessive Size Value
CWE-789Top Fix
Upgrade Version
Upgrade to version github.com/nwaples/rardecode/v2 - v2.2.0;https://github.com/nwaples/rardecode.git - v2.2.0
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | NONE |
| Integrity (I): | NONE |
| Availability (A): | LOW |
Vulnerabilities
Projects
Contact Us


