{"id":"CVE-2025-11579","title":"github.com/nwaples/rardecode: RarDecode Out Of Memory Crash (CVE-2025-11579)","summary":"A memory exhaustion flaw has been discovered in the golang Rar Decode library (github.com/nwaples/rardecode). Affected versions did not limit the size of an archive and so an attacker could provide a crafted archive to a tool or service bu…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","cvssSource":"vendor","cwe":"CWE-789","vendor":"Red Hat","product":"Red Hat Advanced Cluster Security 4","affected":["openshift_serverless","advanced_cluster_security 4","openshift_container_platform 4","trusted_application_pipeline"],"patched":["github.com/nwaples/rardecode/v2 2.2.0"],"published":"2025-10-10","updated":"2026-09-23","sourceUpdated":"2026-09-23T03:37:29+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-11579.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-11579.json"},{"url":"https://access.redhat.com/security/cve/CVE-2025-11579"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2403068"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-11579"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-11579"},{"url":"https://github.com/nwaples/rardecode/commit/52fb4e825c936636f251f7e7deded39ab11df9a9"},{"url":"https://github.com/nwaples/rardecode"},{"url":"https://pkg.go.dev/vuln/GO-2025-4020"}],"tags":["csaf","vex","red-hat","exploit-available","osv","go"],"epss":0.00374,"epssPercentile":0.31336,"exploits":{"github":1,"githubRepos":["https://github.com/shinigami-777/PoC_CVE-2025-11579"],"checkedAt":"2026-09-24T07:52:52.857Z"},"exploitAvailable":true,"aliases":["GHSA-rwvp-r38j-9rgg","GO-2025-4020"],"ecosystem":"go","ingestedAt":"2026-08-07T19:14:17.690Z","slug":"CVE-2025-11579","body":"## Overview\n\nA memory exhaustion flaw has been discovered in the golang Rar Decode library (github.com/nwaples/rardecode). Affected versions did not limit the size of an archive and so an attacker could provide a crafted archive to a tool or service built on Rar decode which might consume more memory than available. This would lead to a program crash.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: OpenShift Serverless, Red Hat Advanced Cluster Security 4, Red Hat OpenShift Container Platform 4, Red Hat Trusted Application Pipeline · no fix planned: OpenShift Serverless, Red Hat Advanced Cluster Security 4, Red Hat OpenShift Container Platform 4, Red Hat Trusted Application Pipeline · updated 2026-09-23 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-11579.json)\n\n**github.com/nwaples/rardecode: RarDecode Out Of Memory Crash** — rated Moderate by Red Hat. Released 2025-10-10, updated 2026-09-23.\n\nAffected:\n\n- OpenShift Serverless\n- Red Hat Advanced Cluster Security 4\n- Red Hat OpenShift Container Platform 4\n- Red Hat Trusted Application Pipeline\n\nNo fix planned:\n\n- OpenShift Serverless\n- Red Hat Advanced Cluster Security 4\n- Red Hat OpenShift Container Platform 4\n- Red Hat Trusted Application Pipeline\n\n## Remediation\n\nFix deferred\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.\n\n## Package advisory (CVE-2025-11579)\n\nAffected packages:\n\n- `github.com/nwaples/rardecode/v2 < 2.2.0`\n- `github.com/nwaples/rardecode <= 1.1.3`\n\nPatched in:\n\n- `github.com/nwaples/rardecode/v2 2.2.0`\n\nSource: https://osv.dev/vulnerability/GHSA-rwvp-r38j-9rgg","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":4783,"id":"CVE-2025-11579","ts":1788887205913,"field":"exploit_available","old":"false","new":"true"},{"seq":3666,"id":"CVE-2025-11579","ts":1788886322682,"field":"exploit_available","old":"true","new":"false"},{"seq":2517,"id":"CVE-2025-11579","ts":1788882990361,"field":"exploit_available","old":"false","new":"true"},{"seq":1546,"id":"CVE-2025-11579","ts":1788882404144,"field":"exploit_available","old":"true","new":"false"},{"seq":660,"id":"CVE-2025-11579","ts":1788881841682,"field":"exploit_available","old":"false","new":"true"}]}