VictoriaMetrics is a scalable solution for monitoring and managing time series data. In versions from 1.0.0 to before 1.110.23, from 1.111.0 to before 1.122.8, and from 1.123.0 to before 1.129.1, affected versions are vulnerable to DoS attacks because the snappy decoder ignored VictoriaMetrics request size limits allowing malformed blocks to trigger excessive memory use. This could lead to OOM errors and service instability. The fix enforces block-size checks based on MaxRequest limits. This issue has been patched in versions 1.110.23, 1.122.8, and 1.129.1.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-66jq-2c23-2xh5 VictoriaMetrics' Snappy Decoder DoS Vulnerability is Causing OOM
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 25 Nov 2025 22:30:00 +0000

Type Values Removed Values Added
Description VictoriaMetrics is a scalable solution for monitoring and managing time series data. In versions from 1.0.0 to before 1.110.23, from 1.111.0 to before 1.122.8, and from 1.123.0 to before 1.129.1, affected versions are vulnerable to DoS attacks because the snappy decoder ignored VictoriaMetrics request size limits allowing malformed blocks to trigger excessive memory use. This could lead to OOM errors and service instability. The fix enforces block-size checks based on MaxRequest limits. This issue has been patched in versions 1.110.23, 1.122.8, and 1.129.1.
Title VictoriaMetrics Snappy Decoder DoS Vulnerability is Causing OOM
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-11-25T22:25:46.021Z

Reserved: 2025-11-18T16:14:56.690Z

Link: CVE-2025-65942

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-11-25T23:15:47.923

Modified: 2025-11-25T23:15:47.923

Link: CVE-2025-65942

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.