CVE-2025-11579EPSS p29.4%
CVE-2025-11579CVE-2025-11579
nwaples / rardecode
Description
github.com/nwaples/rardecode versions <=2.1.1 fail to restrict the dictionary size when reading large RAR dictionary sizes, which allows an attacker to provide a specially crafted RAR file and cause Denial of Service via an Out Of Memory Crash.
Scoring
| CVSS | 5.3 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
| EPSS | 0.37% probability of exploitation · percentile 29.4% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-08 |