github.com/nwaples/rardecode versions <=2.1.1 fail to restrict the dictionary size when reading large RAR dictionary sizes, which allows an attacker to provide a specially crafted RAR file and cause Denial of Service via an Out Of Memory Crash.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-rwvp-r38j-9rgg rardecode: DoS risk due to unrestricted RAR dictionary sizes
Fixes

Solution

Update to github.com/nwaples/rardecode v2.2.0 or higher


Workaround

No workaround given by the vendor.

History

Sat, 17 Jan 2026 06:00:00 +0900

Type Values Removed Values Added
First Time appeared Nwaples
Nwaples rardecode
CPEs cpe:2.3:a:nwaples:rardecode:*:*:*:*:*:go:*:*
Vendors & Products Nwaples
Nwaples rardecode

Tue, 02 Dec 2025 19:30:00 +0900

Type Values Removed Values Added
Weaknesses CWE-306
References

Tue, 02 Dec 2025 18:45:00 +0900

Type Values Removed Values Added
Description Mattermost versions 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate the user permission when accessing the files and subscribing to the block in Boards, which allows an authenticated user to access other board files and was able to subscribe to the block from other boards that the user does not have access to github.com/nwaples/rardecode versions <=2.1.1 fail to restrict the dictionary size when reading large RAR dictionary sizes, which allows an attacker to provide a specially crafted RAR file and cause Denial of Service via an Out Of Memory Crash.
Title Unauthorized access and subscription vulnerability in Boards DoS via Out Of Memory Crash
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Thu, 27 Nov 2025 21:00:00 +0900

Type Values Removed Values Added
Description github.com/nwaples/rardecode versions <=2.1.1 fail to restrict the dictionary size when reading large RAR dictionary sizes, which allows an attacker to provide a specially crafted RAR file and cause Denial of Service via an Out Of Memory Crash. Mattermost versions 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate the user permission when accessing the files and subscribing to the block in Boards, which allows an authenticated user to access other board files and was able to subscribe to the block from other boards that the user does not have access to
Title DoS via Out Of Memory Crash Unauthorized access and subscription vulnerability in Boards
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Sat, 11 Oct 2025 09:15:00 +0900

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 10 Oct 2025 22:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Oct 2025 20:30:00 +0900

Type Values Removed Values Added
Description github.com/nwaples/rardecode versions <=2.1.1 fail to restrict the dictionary size when reading large RAR dictionary sizes, which allows an attacker to provide a specially crafted RAR file and cause Denial of Service via an Out Of Memory Crash.
Title DoS via Out Of Memory Crash
Weaknesses CWE-789
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2025-12-02T09:30:03.452Z

Reserved: 2025-10-10T09:12:41.410Z

Link: CVE-2025-11579

cve-icon Vulnrichment

Updated: 2025-10-10T12:41:18.185Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-10T12:15:37.743

Modified: 2026-01-16T20:56:26.367

Link: CVE-2025-11579

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-10-10T11:15:15Z

Links: CVE-2025-11579 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses