CVE-2025-65942

Source
https://cve.org/CVERecord?id=CVE-2025-65942
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-65942.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-65942
Aliases
Downstream
Related
Published
2025-11-25T22:25:46.021Z
Modified
2026-04-18T04:16:54.690918Z
Severity
  • 2.7 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
VictoriaMetrics Snappy Decoder DoS Vulnerability is Causing OOM
Details

VictoriaMetrics is a scalable solution for monitoring and managing time series data. In versions from 1.0.0 to before 1.110.23, from 1.111.0 to before 1.122.8, and from 1.123.0 to before 1.129.1, affected versions are vulnerable to DoS attacks because the snappy decoder ignored VictoriaMetrics request size limits allowing malformed blocks to trigger excessive memory use. This could lead to OOM errors and service instability. The fix enforces block-size checks based on MaxRequest limits. This issue has been patched in versions 1.110.23, 1.122.8, and 1.129.1.

Database specific
{
    "cwe_ids": [
        "CWE-770"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/65xxx/CVE-2025-65942.json"
}
References

Affected packages

Git / github.com/VictoriaMetrics/VictoriaMetrics

Affected ranges

Type
GIT
Repo
https://github.com/VictoriaMetrics/VictoriaMetrics
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.110.23"
        },
        {
            "introduced": "0"
        },
        {
            "fixed": "1.122.8"
        },
        {
            "introduced": "0"
        },
        {
            "fixed": "1.129.1"
        }
    ]
}
Type
GIT
Repo
https://github.com/victoriametrics/victoriametrics
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Fixed

Affected versions

v0.*
v0.1.0-victorialogs
v0.10.0-victorialogs
v0.11.0-victorialogs
v0.12.0-victorialogs
v0.12.1-victorialogs
v0.13.0-victorialogs
v0.14.0-victorialogs
v0.15.0-victorialogs
v0.16.0-victorialogs
v0.17.0-victorialogs
v0.18.0-victorialogs
v0.19.0-victorialogs
v0.2.0-victorialogs
v0.20.0-victorialogs
v0.20.1-victorialogs
v0.20.2-victorialogs
v0.21.0-victorialogs
v0.22.0-victorialogs
v0.23.0-victorialogs
v0.24.0-victorialogs
v0.25.0-victorialogs
v0.26.0-victorialogs
v0.26.1-victorialogs
v0.27.0-victorialogs
v0.27.1-victorialogs
v0.28.0-victorialogs
v0.29.0-victorialogs
v0.3.0-victorialogs
v0.30.0-victorialogs
v0.30.1-victorialogs
v0.31.0-victorialogs
v0.32.0-victorialogs
v0.32.1-victorialogs
v0.33.0-victorialogs
v0.34.0-victorialogs
v0.35.0-victorialogs
v0.36.0-victorialogs
v0.37.0-victorialogs
v0.38.0-victorialogs
v0.39.0-victorialogs
v0.4.0-victorialogs
v0.4.2-victorialogs
v0.40.0-victorialogs
v0.41.0-victorialogs
v0.42.0-victorialogs
v0.5.0-victorialogs
v0.5.1-victorialogs
v0.5.2-victorialogs
v0.6.0-victorialogs
v0.6.1-victorialogs
v0.7.0-victorialogs
v0.8.0-victorialogs
v0.9.0-victorialogs
v0.9.1-victorialogs
v1.*
v1.0.0-victorialogs
v1.1.0-victorialogs
v1.10.0
v1.10.0-victorialogs
v1.10.1
v1.10.1-victorialogs
v1.100.0
v1.100.0-cluster
v1.100.1
v1.100.1-cluster
v1.101.0
v1.101.0-cluster
v1.102.0
v1.102.0-cluster
v1.102.0-rc1
v1.102.0-rc1-cluster
v1.102.0-rc2
v1.102.0-rc2-cluster
v1.102.1
v1.102.1-cluster
v1.102.10
v1.102.11
v1.102.12
v1.102.13
v1.102.14
v1.102.15
v1.102.16
v1.102.17
v1.102.18
v1.102.19
v1.102.2
v1.102.20
v1.102.21
v1.102.22
v1.102.23
v1.102.24
v1.102.25
v1.102.26
v1.102.3
v1.102.4
v1.102.5
v1.102.6
v1.102.7
v1.102.8
v1.102.9
v1.103.0
v1.103.0-cluster
v1.104.0
v1.104.0-cluster
v1.105.0
v1.105.0-cluster
v1.106.0
v1.106.0-cluster
v1.106.1
v1.106.1-cluster
v1.108.1
v1.108.1-cluster
v1.109.0
v1.109.0-cluster
v1.109.1
v1.109.1-cluster
v1.11.0
v1.11.0-victorialogs
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.110.1
v1.110.10
v1.110.11
v1.110.12
v1.110.13
v1.110.14
v1.110.15
v1.110.16
v1.110.17
v1.110.18
v1.110.19
v1.110.2
v1.110.20
v1.110.21
v1.110.22
v1.110.3
v1.110.4
v1.110.5
v1.110.6
v1.110.7
v1.110.8
v1.110.9
v1.111.0
v1.111.0-cluster
v1.113.0
v1.113.0-cluster
v1.114.0
v1.114.0-cluster
v1.115.0
v1.115.0-cluster
v1.117.0
v1.117.0-cluster
v1.117.1
v1.117.1-cluster
v1.118.0
v1.118.0-cluster
v1.119.0
v1.119.0-cluster
v1.12.0
v1.12.0-victorialogs
v1.12.1
v1.12.2
v1.12.3
v1.12.4
v1.12.5
v1.12.6
v1.120.0
v1.120.0-cluster
v1.121.0
v1.121.0-cluster
v1.122.0
v1.122.0-cluster
v1.122.1
v1.122.2
v1.122.3
v1.122.4
v1.122.5
v1.122.6
v1.122.7
v1.123.0
v1.123.0-cluster
v1.124.0
v1.124.0-cluster
v1.125.0
v1.125.0-cluster
v1.125.1
v1.125.1-cluster
v1.126.0
v1.126.0-cluster
v1.127.0
v1.127.0-cluster
v1.128.0
v1.128.0-cluster
v1.129.0
v1.129.0-cluster
v1.129.1
v1.13.0
v1.13.0-victorialogs
v1.13.1
v1.14.0
v1.14.0-victorialogs
v1.14.1
v1.14.2
v1.15.0
v1.15.0-victorialogs
v1.15.1
v1.15.2
v1.16.0
v1.16.0-victorialogs
v1.17.0
v1.17.0-victorialogs
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.17.5
v1.18.0
v1.18.0-victorialogs
v1.18.1
v1.18.10
v1.18.11
v1.18.3
v1.18.4
v1.18.5
v1.18.6
v1.18.7
v1.18.8
v1.18.9
v1.19.0
v1.19.0-victorialogs
v1.19.1
v1.19.2
v1.19.3
v1.19.4
v1.2.0-victorialogs
v1.2.1
v1.20.0
v1.20.0-victorialogs
v1.20.1
v1.20.2
v1.20.3
v1.20.4
v1.20.5
v1.20.6
v1.20.7
v1.21.0
v1.21.0-victorialogs
v1.21.1
v1.21.2
v1.22.0
v1.22.0-victorialogs
v1.22.1
v1.22.1-victorialogs
v1.22.2
v1.22.2-victorialogs
v1.23.0
v1.23.0-cluster
v1.23.0-victorialogs
v1.23.1
v1.23.1-cluster
v1.23.1-victorialogs
v1.23.2-victorialogs
v1.23.3-victorialogs
v1.24.0
v1.24.0-cluster
v1.24.0-victorialogs
v1.24.1
v1.24.1-cluster
v1.25.0
v1.25.0-cluster
v1.25.1
v1.25.1-cluster
v1.25.2
v1.25.2-cluster
v1.26.0
v1.26.0-cluster
v1.27.0
v1.27.0-cluster
v1.27.1
v1.27.1-cluster
v1.27.2
v1.27.2-cluster
v1.27.3
v1.27.3-cluster
v1.28.0
v1.28.0-beta1
v1.28.0-beta2
v1.28.0-beta3
v1.28.0-beta4
v1.28.0-beta5
v1.28.0-beta6
v1.28.0-cluster
v1.28.0-cluster-beta1
v1.28.0-cluster-beta2
v1.28.0-cluster-beta3
v1.28.0-cluster-beta4
v1.28.0-cluster-beta5
v1.28.0-cluster-beta6
v1.28.1
v1.28.1-cluster
v1.28.2
v1.28.2-cluster
v1.28.3
v1.28.3-cluster
v1.29.0
v1.29.0-cluster
v1.29.1
v1.29.1-cluster
v1.29.2
v1.29.2-cluster
v1.29.3
v1.29.3-cluster
v1.29.4
v1.29.4-cluster
v1.29.5
v1.29.5-cluster
v1.3.0
v1.3.0-victorialogs
v1.3.1
v1.3.1-victorialogs
v1.3.2
v1.3.2-victorialogs
v1.30.0
v1.30.0-cluster
v1.30.1
v1.30.1-cluster
v1.30.2
v1.30.2-cluster
v1.30.3
v1.30.3-cluster
v1.30.4
v1.30.4-cluster
v1.30.5
v1.30.5-cluster
v1.30.6
v1.30.6-cluster
v1.31.0
v1.31.0-cluster
v1.31.1
v1.31.1-cluster
v1.31.2
v1.31.2-cluster
v1.31.3
v1.31.3-cluster
v1.31.4
v1.31.4-cluster
v1.31.5
v1.31.5-cluster
v1.32.0
v1.32.0-cluster
v1.32.1
v1.32.1-cluster
v1.32.2
v1.32.2-cluster
v1.32.3
v1.32.3-cluster
v1.32.4
v1.32.4-cluster
v1.32.5
v1.32.5-cluster
v1.32.6
v1.32.6-cluster
v1.32.7
v1.32.7-cluster
v1.32.8
v1.32.8-cluster
v1.33.0
v1.33.0-cluster
v1.33.1
v1.33.1-cluster
v1.34.0
v1.34.0-cluster
v1.34.1
v1.34.1-cluster
v1.34.2
v1.34.2-cluster
v1.34.3
v1.34.3-cluster
v1.34.4
v1.34.4-cluster
v1.34.5
v1.34.5-cluster
v1.34.6
v1.34.6-cluster
v1.34.7
v1.34.7-cluster
v1.34.8
v1.34.8-cluster
v1.34.9
v1.34.9-cluster
v1.35.0
v1.35.0-cluster
v1.35.1
v1.35.1-cluster
v1.35.2
v1.35.2-cluster
v1.35.3
v1.35.3-cluster
v1.35.4
v1.35.4-cluster
v1.35.5
v1.35.5-cluster
v1.35.6
v1.35.6-cluster
v1.36.0
v1.36.0-cluster
v1.36.1
v1.36.1-cluster
v1.36.2
v1.36.2-cluster
v1.36.3
v1.36.3-cluster
v1.37.0
v1.37.0-cluster
v1.37.1
v1.37.1-cluster
v1.37.2
v1.37.2-cluster
v1.37.3
v1.37.3-cluster
v1.37.4
v1.37.4-cluster
v1.38.0
v1.38.0-cluster
v1.38.1
v1.38.1-cluster
v1.39.0
v1.39.0-cluster
v1.39.1
v1.39.1-cluster
v1.39.2
v1.39.2-cluster
v1.39.3
v1.39.3-cluster
v1.39.4
v1.39.4-cluster
v1.4.0
v1.4.0-victorialogs
v1.40.0
v1.40.0-cluster
v1.40.1
v1.40.1-cluster
v1.41.0
v1.41.0-cluster
v1.41.1
v1.41.1-cluster
v1.42.0
v1.42.0-cluster
v1.43.0
v1.43.0-cluster
v1.44.0
v1.44.0-cluster
v1.45.0
v1.45.0-cluster
v1.46.0
v1.46.0-cluster
v1.47.0
v1.47.0-cluster
v1.48.0
v1.48.0-cluster
v1.49.0
v1.49.0-cluster
v1.5.0
v1.5.0-victorialogs
v1.5.1
v1.50.0
v1.50.0-cluster
v1.50.1
v1.50.1-cluster
v1.50.2
v1.50.2-cluster
v1.51.0
v1.51.0-cluster
v1.52.0
v1.52.0-cluster
v1.53.0
v1.53.0-cluster
v1.53.1-cluster
v1.54.0
v1.54.0-cluster
v1.54.1
v1.54.1-cluster
v1.55.0
v1.55.0-cluster
v1.55.1
v1.55.1-cluster
v1.56.0
v1.56.0-cluster
v1.57.0
v1.57.0-cluster
v1.57.1
v1.57.1-cluster
v1.58.0
v1.58.0-cluster
v1.59.0
v1.59.0-cluster
v1.6.0
v1.6.0-victorialogs
v1.6.1
v1.6.1-victorialogs
v1.6.2
v1.60.0
v1.60.0-cluster
v1.61.0
v1.61.0-cluster
v1.61.1
v1.61.1-cluster
v1.62.0
v1.62.0-cluster
v1.63.0
v1.63.0-cluster
v1.64.0
v1.64.0-cluster
v1.64.1
v1.64.1-cluster
v1.65.0
v1.65.0-cluster
v1.66.0
v1.66.0-cluster
v1.66.1
v1.66.1-cluster
v1.66.2
v1.66.2-cluster
v1.67.0
v1.67.0-cluster
v1.68.0
v1.68.0-cluster
v1.69.0
v1.69.0-cluster
v1.7.0
v1.7.0-victorialogs
v1.7.1
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.70.0
v1.70.0-cluster
v1.71.0
v1.71.0-cluster
v1.72.0
v1.72.0-cluster
v1.73.0
v1.73.0-cluster
v1.73.1
v1.73.1-cluster
v1.74.0
v1.74.0-cluster
v1.75.0
v1.75.0-cluster
v1.76.0
v1.76.0-cluster
v1.76.1
v1.76.1-cluster
v1.77.0
v1.77.0-cluster
v1.77.1
v1.77.1-cluster
v1.77.2
v1.77.2-cluster
v1.78.0
v1.78.0-cluster
v1.79.0
v1.79.0-cluster
v1.8.0
v1.8.0-victorialogs
v1.8.1
v1.8.2
v1.80.0
v1.80.0-cluster
v1.81.0
v1.81.0-cluster
v1.81.1
v1.81.1-cluster
v1.82.0
v1.82.0-cluster
v1.83.0
v1.83.0-cluster
v1.83.1
v1.83.1-cluster
v1.84.0
v1.84.0-cluster
v1.85.0
v1.85.0-cluster
v1.85.1
v1.85.1-cluster
v1.85.2
v1.85.2-cluster
v1.85.3
v1.85.3-cluster
v1.86.0
v1.86.0-cluster
v1.86.1
v1.86.1-cluster
v1.86.2
v1.86.2-cluster
v1.87.0
v1.87.0-cluster
v1.87.1
v1.87.1-cluster
v1.88.0
v1.88.0-cluster
v1.88.1
v1.88.1-cluster
v1.89.0
v1.89.0-cluster
v1.89.1
v1.89.1-cluster
v1.9.0
v1.9.0-victorialogs
v1.9.1-victorialogs
v1.90.0
v1.90.0-cluster
v1.91.0
v1.91.0-cluster
v1.91.1
v1.91.2
v1.91.2-cluster
v1.92.0
v1.92.0-cluster
v1.92.1
v1.92.1-cluster
v1.93.0
v1.93.0-cluster
v1.94.0
v1.94.0-cluster
v1.95.0
v1.95.0-cluster
v1.95.1
v1.95.1-cluster
v1.96.0
v1.96.0-cluster
v1.97.0
v1.97.0-cluster
v1.97.1
v1.97.1-cluster
v1.97.10
v1.97.11
v1.97.12
v1.97.13
v1.97.14
v1.97.15
v1.97.16
v1.97.17
v1.97.2
v1.97.3
v1.97.4
v1.97.5
v1.97.6
v1.97.7
v1.97.8
v1.97.9
v1.98.0
v1.98.0-cluster
v1.99.0
v1.99.0-cluster

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-65942.json"