Description

github.com/nwaples/rardecode versions <=2.1.1 fail to restrict the dictionary size when reading large RAR dictionary sizes, which allows an attacker to provide a specially crafted RAR file and cause Denial of Service via an Out Of Memory Crash.

INFO

Published Date :

2025-10-10T11:15:15.163Z

Last Modified :

2025-12-02T09:30:03.452Z

Source :

Mattermost
AFFECTED PRODUCTS

The following products are affected by CVE-2025-11579 vulnerability.

Vendors Products
Nwaples
  • Rardecode
REFERENCES

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact