Description

A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line payload larger than 64KB without newline characters. Due to limitations in the internal bufio.Scanner, the read fails with "token too long" and the writer pipe is closed, leaving Writer() unusable and causing application unavailability (DoS). This affects versions < 1.8.3, 1.9.0, and 1.9.2. The issue is fixed in 1.8.3, 1.9.1, and 1.9.3+, where the input is chunked and the writer continues to function even if an error is logged.

INFO

Published Date :

2025-12-04T00:00:00.000Z

Last Modified :

2025-12-05T21:52:59.784Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2025-65637 vulnerability.

Vendors Products
Logrus Project
  • Logrus
Turbopuffer
  • Logrus

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact