PT-2025-16351 · Yauzl+1 · Yauzl+1

Ori Hollander

·

Published

2025-04-15

·

Updated

2025-04-15

·

CVE-2025-32949

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions PeerTube (affected versions not specified)
Description This issue allows any authenticated user to cause the server to consume large amounts of disk space by extracting a Zip Bomb. When user import is enabled, which is the default setting, any registered user can upload an archive for importing. The yauzl library used for reading the archive lacks a mechanism to detect or prevent extraction of a Zip Bomb, leading to disk space resource exhaustion when using the User Import functionality with a Zip Bomb.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Weakness Enumeration

Related Identifiers

CVE-2025-32949

Affected Products

Peertube
Yauzl