PT-2025-46208 · Bugsink · Bugsink
Published
2025-11-10
·
Updated
2025-11-13
·
CVE-2025-64509
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Bugsink versions prior to 2.0.6
Description
Bugsink is a self-hosted error tracking tool. A specially crafted Brotli-compressed envelope can cause Bugsink to expend excessive CPU time during decompression, resulting in a denial of service. This is possible if the Data Source Name (DSN) is known, which is common in many configurations like JavaScript and Mobile Apps. This issue is distinct from another Brotli-related problem in Bugsink.
Recommendations
Update to Bugsink version 2.0.6 or later.
Exploit
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bugsink