FlawAtlas
Search the atlas
CVE-2025-11579 Moderate

rardecode: DoS risk due to unrestricted RAR dictionary sizes

rardecode versions <= 2.1.1 fail to restrict the dictionary size when reading large RAR dictionary sizes, which allows an attacker to provide a specially crafted RAR file and cause Denial of Service via an Out Of Memory Crash.

Exploit probability 0.3%
Published October 10, 2025
Required by Not available
Last source change August 7, 2026

02 / AFFECTED SOFTWARE

Affected packages

Go github.com/nwaples/rardecode
Go github.com/nwaples/rardecode/v2
Go github.com/nwaples/rardecode
Go github.com/nwaples/rardecode/v2
Unknown Unknown

8 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2025-11579

github.com/nwaples/rardecode versions <=2.1.1 fail to restrict the dictionary size when reading large RAR dictionary sizes, which allows an attacker to provide a specially crafted RAR file and cause Denial of Service via an Out Of Memory Crash.

View original source
Open Source Vulnerabilities GO-2025-4020

DoS risk due to unrestricted RAR dictionary sizes in github.com/nwaples/rardecode

View original source
Open Source Vulnerabilities GHSA-rwvp-r38j-9rgg

rardecode versions <= 2.1.1 fail to restrict the dictionary size when reading large RAR dictionary sizes, which allows an attacker to provide a specially crafted RAR file and cause Denial of Service via an Out Of Memory Crash.

View original source

05 / REFERENCES

Further evidence