PT-2025-46208 · Bugsink · Bugsink

Published

2025-11-10

·

Updated

2025-11-13

·

CVE-2025-64509

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Bugsink versions prior to 2.0.6
Description Bugsink is a self-hosted error tracking tool. A specially crafted Brotli-compressed envelope can cause Bugsink to expend excessive CPU time during decompression, resulting in a denial of service. This is possible if the Data Source Name (DSN) is known, which is common in many configurations like JavaScript and Mobile Apps. This issue is distinct from another Brotli-related problem in Bugsink.
Recommendations Update to Bugsink version 2.0.6 or later.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2025-64509
GHSA-RRX3-2X4G-MQ2H

Affected Products

Bugsink