Denial of Service Vulnerability in VictoriaMetrics by VictoriaMetrics
CVE-2025-65942

2.7LOW

Key Information:

Vendor
CVE Published:
25 November 2025

What is CVE-2025-65942?

VictoriaMetrics, a solution for monitoring and managing time series data, is vulnerable to denial of service attacks in certain versions. The issue arises from the snappy decoder, which fails to enforce request size limitations, allowing maliciously crafted blocks to consume excessive memory. This can lead to out-of-memory (OOM) errors and overall service instability. Users are encouraged to update to patched versions 1.110.23, 1.122.8, or 1.129.1 to mitigate this vulnerability.

Affected Version(s)

VictoriaMetrics >= 1.0.0, < 1.110.23 < 1.0.0, 1.110.23

VictoriaMetrics >= 1.111.0, < 1.122.8 < 1.111.0, 1.122.8

VictoriaMetrics >= 1.123.0, < 1.129.1 < 1.123.0, 1.129.1

References

CVSS V3.1

Score:
2.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.