CVE-2025-30160

HIGH

redlib < 0.36.0 - Denial of Service via Base2048-Encoded DEFLATE Decompression Bomb

Title source: llm
STIX 2.1

Description

Redlib is an alternative private front-end to Reddit. A vulnerability has been identified in Redlib where an attacker can cause a denial-of-service (DOS) condition by submitting a specially crafted base2048-encoded DEFLATE decompression bomb to the restore_preferences form. This leads to excessive memory consumption and potential system instability, which can be exploited to disrupt Redlib instances. This vulnerability is fixed in 0.36.0.

Scores

CVSS v3 7.5
EPSS 0.0050
EPSS Percentile 38.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-400 CWE-502
Status published
Products (2)
crates.io/redlib 0 - 0.36.0crates.io
redlib/redlib < 0.36.0
Published Mar 20, 2025
Tracked Since Feb 18, 2026