CVE-2025-32944

MEDIUM

PeerTube - DoS

Title source: llm

Description

The vulnerability allows any authenticated user to cause the PeerTube server to stop functioning in a persistent manner.  If user import is enabled (which is the default setting), any registered user can upload an archive for importing. The code uses the yauzl library for reading the archive. If the yauzl library encounters a filename that is considered illegal, it raises an exception that is uncaught by PeerTube, leading to a crash which repeats infinitely on startup.

Scores

CVSS v3 6.5
EPSS 0.0004
EPSS Percentile 11.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Classification

CWE
CWE-248
Status published

Affected Products (1)

framasoft/peertube < 7.1.1

Timeline

Published Apr 15, 2025
Tracked Since Feb 18, 2026