PT-2025-12367 · Redlib · Redlib

Published

2025-03-20

·

Updated

2026-02-03

·

CVE-2025-30160

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Redlib versions prior to 0.36.0
Description A denial-of-service condition can be triggered by submitting a specially crafted base2048-encoded DEFLATE decompression bomb to the restore preferences form, leading to excessive memory consumption and potential system instability. This can disrupt Redlib instances.
Recommendations For versions prior to 0.36.0, update to version 0.36.0 to resolve the issue. As a temporary workaround, consider restricting access to the restore preferences form to minimize the risk of exploitation.

Exploit

Fix

DoS

Resource Exhaustion

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2025-30160
GHSA-G8VQ-V3MG-7MRG

Affected Products

Redlib