CVE-2025-65942 - CVE House
Back to Database
Status published Low CVE-2025-65942

VictoriaMetrics Snappy Decoder DoS Vulnerability is Causing OOM

Vulnerability Description

VictoriaMetrics is a scalable solution for monitoring and managing time series data. In versions from 1.0.0 to before 1.110.23, from 1.111.0 to before 1.122.8, and from 1.123.0 to before 1.129.1, affected versions are vulnerable to DoS attacks because the snappy decoder ignored VictoriaMetrics request size limits allowing malformed blocks to trigger excessive memory use. This could lead to OOM errors and service instability. The fix enforces block-size checks based on MaxRequest limits. This issue has been patched in versions 1.110.23, 1.122.8, and 1.129.1.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-65942

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

VictoriaMetrics

View all reports →

Affected Software

VictoriaMetrics
Vulnerable Versions:
>= 1.0.0, < 1.110.23, >= 1.111.0, < 1.122.8, >= 1.123.0, < 1.129.1

Timeline

Official Publish: November 25th, 2025
Last Modified: November 26th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L

Weaknesses (CWE)