Логотип exploitDog
bind:"GHSA-4f99-4q7p-p3gh" OR bind:"CVE-2025-65637"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-4f99-4q7p-p3gh" OR bind:"CVE-2025-65637"

Количество 8

Количество 8

github логотип

GHSA-4f99-4q7p-p3gh

4 месяца назад

Logrus is vulnerable to DoS when using Entry.Writer()

EPSS: Низкий
ubuntu логотип

CVE-2025-65637

4 месяца назад

A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line payload larger than 64KB without newline characters. Due to limitations in the internal bufio.Scanner, the read fails with "token too long" and the writer pipe is closed, leaving Writer() unusable and causing application unavailability (DoS). This affects versions < 1.8.3, 1.9.0, and 1.9.2. The issue is fixed in 1.8.3, 1.9.1, and 1.9.3+, where the input is chunked and the writer continues to function even if an error is logged.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2025-65637

4 месяца назад

A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line payload larger than 64KB without newline characters. Due to limitations in the internal bufio.Scanner, the read fails with "token too long" and the writer pipe is closed, leaving Writer() unusable and causing application unavailability (DoS). This affects versions < 1.8.3, 1.9.0, and 1.9.2. The issue is fixed in 1.8.3, 1.9.1, and 1.9.3+, where the input is chunked and the writer continues to function even if an error is logged.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-65637

4 месяца назад

A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line payload larger than 64KB without newline characters. Due to limitations in the internal bufio.Scanner, the read fails with "token too long" and the writer pipe is closed, leaving Writer() unusable and causing application unavailability (DoS). This affects versions < 1.8.3, 1.9.0, and 1.9.2. The issue is fixed in 1.8.3, 1.9.1, and 1.9.3+, where the input is chunked and the writer continues to function even if an error is logged.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2025-65637

4 месяца назад

A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line payload larger than 64KB without newline characters.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2025-65637

4 месяца назад

A denial-of-service vulnerability exists in github.com/sirupsen/logrus ...

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2026:3428

27 дней назад

Important: container-tools:rhel8 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-3428

29 дней назад

ELSA-2026-3428: container-tools:ol8 security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4f99-4q7p-p3gh

Logrus is vulnerable to DoS when using Entry.Writer()

0%
Низкий
4 месяца назад
ubuntu логотип
CVE-2025-65637

A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line payload larger than 64KB without newline characters. Due to limitations in the internal bufio.Scanner, the read fails with "token too long" and the writer pipe is closed, leaving Writer() unusable and causing application unavailability (DoS). This affects versions < 1.8.3, 1.9.0, and 1.9.2. The issue is fixed in 1.8.3, 1.9.1, and 1.9.3+, where the input is chunked and the writer continues to function even if an error is logged.

CVSS3: 7.5
0%
Низкий
4 месяца назад
redhat логотип
CVE-2025-65637

A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line payload larger than 64KB without newline characters. Due to limitations in the internal bufio.Scanner, the read fails with "token too long" and the writer pipe is closed, leaving Writer() unusable and causing application unavailability (DoS). This affects versions < 1.8.3, 1.9.0, and 1.9.2. The issue is fixed in 1.8.3, 1.9.1, and 1.9.3+, where the input is chunked and the writer continues to function even if an error is logged.

CVSS3: 7.5
0%
Низкий
4 месяца назад
nvd логотип
CVE-2025-65637

A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line payload larger than 64KB without newline characters. Due to limitations in the internal bufio.Scanner, the read fails with "token too long" and the writer pipe is closed, leaving Writer() unusable and causing application unavailability (DoS). This affects versions < 1.8.3, 1.9.0, and 1.9.2. The issue is fixed in 1.8.3, 1.9.1, and 1.9.3+, where the input is chunked and the writer continues to function even if an error is logged.

CVSS3: 7.5
0%
Низкий
4 месяца назад
msrc логотип
CVE-2025-65637

A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line payload larger than 64KB without newline characters.

CVSS3: 5.9
0%
Низкий
4 месяца назад
debian логотип
CVE-2025-65637

A denial-of-service vulnerability exists in github.com/sirupsen/logrus ...

CVSS3: 7.5
0%
Низкий
4 месяца назад
rocky логотип
RLSA-2026:3428

Important: container-tools:rhel8 security update

27 дней назад
oracle-oval логотип
ELSA-2026-3428

ELSA-2026-3428: container-tools:ol8 security update (IMPORTANT)

29 дней назад

Уязвимостей на страницу