CVE-2025-30160
HIGHRedlib <0.36.0 - DoS
Title source: llmDescription
Redlib is an alternative private front-end to Reddit. A vulnerability has been identified in Redlib where an attacker can cause a denial-of-service (DOS) condition by submitting a specially crafted base2048-encoded DEFLATE decompression bomb to the restore_preferences form. This leads to excessive memory consumption and potential system instability, which can be exploited to disrupt Redlib instances. This vulnerability is fixed in 0.36.0.
Scores
CVSS v3
7.5
EPSS
0.0047
EPSS Percentile
64.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Classification
CWE
CWE-502
CWE-400
Status
published
Affected Products (2)
redlib/redlib
< 0.36.0
crates.io/redlib
< 0.36.0crates.io
Timeline
Published
Mar 20, 2025
Tracked Since
Feb 18, 2026