github.com/victoriametrics/victoriametrics is vulnerable to Allocation of Resources Without Limits or Throttling
30
Low Risk
Affected versions of this package are vulnerable to Improper Memory Limit Enforcement on zstd Encoded Requests, where the maxDataSize memory limits are not correctly applied to zstd compressed requests, undermining the protection for ingest endpoints against malicious payloads. An attacker could exploit this by sending a specially crafted zstd encoded request that exceeds memory constraints, potentially leading to resource exhaustion, denial of service, or unauthorized system access.
You are affected if you are using a version that falls within the vulnerable range.
github.com/victoriametrics/victoriametrics is vulnerable to Allocation of Resources Without Limits or Throttling in versions 1.123.0 - 1.129.1, 1.111.0 - 1.122.8 and 1.18.3 - 1.110.23.
Upgrade the github.com/victoriametrics/victoriametrics library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant