High severityNVD Advisory· Published Mar 20, 2025· Updated Mar 20, 2025
Redlib allows a Denial of Service via DEFLATE Decompression Bomb in restore_preferences Form
CVE-2025-30160
Description
Redlib is an alternative private front-end to Reddit. A vulnerability has been identified in Redlib where an attacker can cause a denial-of-service (DOS) condition by submitting a specially crafted base2048-encoded DEFLATE decompression bomb to the restore_preferences form. This leads to excessive memory consumption and potential system instability, which can be exploited to disrupt Redlib instances. This vulnerability is fixed in 0.36.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
redlibcrates.io | < 0.36.0 | 0.36.0 |
Affected products
2- redlib-org/redlibv5Range: < 0.36.0
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-g8vq-v3mg-7mrgghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-30160ghsaADVISORY
- github.com/crewjam/saml/security/advisories/GHSA-5mqj-xc49-246pghsaWEB
- github.com/redlib-org/redlib/commit/15147cea8e42f6569a11603d661d71122f6a02dcghsax_refsource_MISCWEB
- github.com/redlib-org/redlib/commit/2e95e1fc6e2064ccfae87964b4860bda55eddb9aghsax_refsource_MISCWEB
- github.com/redlib-org/redlib/security/advisories/GHSA-g8vq-v3mg-7mrgghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.