Intel

AIKIDO-2025-10820

github.com/victoriametrics/victoriametrics is vulnerable to Allocation of Resources Without Limits or Throttling

Allocation of Resources Without Limits or Throttling Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Nov 19, 2025

30

Low Risk

This Affects:

GOgithub.com/victoriametrics/victoriametrics
1.18.3 - 1.110.23
Fixed in 1.110.24
1.111.0 - 1.122.8
Fixed in 1.122.9
1.123.0 - 1.129.1
Fixed in 1.130.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Improper Memory Limit Enforcement on zstd Encoded Requests, where the maxDataSize memory limits are not correctly applied to zstd compressed requests, undermining the protection for ingest endpoints against malicious payloads. An attacker could exploit this by sending a specially crafted zstd encoded request that exceeds memory constraints, potentially leading to resource exhaustion, denial of service, or unauthorized system access.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/victoriametrics/victoriametrics is vulnerable to Allocation of Resources Without Limits or Throttling in versions 1.123.0 - 1.129.1, 1.111.0 - 1.122.8 and 1.18.3 - 1.110.23.

How to fix this

Upgrade the github.com/victoriametrics/victoriametrics library to the patch version.