VictoriaMetrics' Snappy Decoder DoS Vulnerability is Causing OOM in github.com/VictoriaMetrics/VictoriaMetrics
{
"url": "https://pkg.go.dev/vuln/GO-2025-4161",
"review_status": "REVIEWED"
}{
"custom_ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "1.0.0"
}
]
}
],
"imports": [
{
"symbols": [
"Parse"
],
"path": "github.com/VictoriaMetrics/VictoriaMetrics/lib/protoparser/promremotewrite/stream"
},
{
"symbols": [
"GetUncompressedReader",
"ReadUncompressedData",
"snappyReader.Reset"
],
"path": "github.com/VictoriaMetrics/VictoriaMetrics/lib/protoparser/protoparserutil"
}
]
}