Intel

AIKIDO-2025-10786

github.com/victoriametrics/victoriametrics is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)CVE-2025-65942 Published Nov 10, 2025

31

Low Risk

This Affects:

GOgithub.com/victoriametrics/victoriametrics
1.18.3 - 1.110.22
Fixed in 1.110.23
1.111.0 - 1.122.7
Fixed in 1.122.8
1.123.0 - 1.129.0
Fixed in 1.129.1
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to denial-of-service (DoS) attacks. The snappy decoder failed to respect request size limits enforced by VictoriaMetrics components, allowing malformed snappy blocks to trigger excessive memory allocations. This could result in out-of-memory (OOM) errors and service instability. The fix enforces block size validation in ingest endpoints based on the configured MaxRequest limits.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/victoriametrics/victoriametrics is vulnerable to Denial of Service (DoS) in versions 1.123.0 - 1.129.0, 1.111.0 - 1.122.7 and 1.18.3 - 1.110.22.

How to fix this

Upgrade the github.com/victoriametrics/victoriametrics library to the patch version.