---
id: CVE-2025-11579
title: 'github.com/nwaples/rardecode: RarDecode Out Of Memory Crash (CVE-2025-11579)'
summary: >-
  A memory exhaustion flaw has been discovered in the golang Rar Decode library
  (github.com/nwaples/rardecode). Affected versions did not limit the size of an
  archive and so an attacker could provide a crafted archive to a tool or
  service bu…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'
cvssSource: vendor
cwe: CWE-789
vendor: Red Hat
product: Red Hat Advanced Cluster Security 4
affected:
  - openshift_serverless
  - advanced_cluster_security 4
  - openshift_container_platform 4
  - trusted_application_pipeline
patched:
  - github.com/nwaples/rardecode/v2 2.2.0
published: '2025-10-10'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T03:37:29+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-11579.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-11579.json
  - url: 'https://access.redhat.com/security/cve/CVE-2025-11579'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2403068'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-11579'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11579'
  - url: >-
      https://github.com/nwaples/rardecode/commit/52fb4e825c936636f251f7e7deded39ab11df9a9
  - url: 'https://github.com/nwaples/rardecode'
  - url: 'https://pkg.go.dev/vuln/GO-2025-4020'
tags:
  - csaf
  - vex
  - red-hat
  - exploit-available
  - osv
  - go
epss: 0.00374
epssPercentile: 0.28663
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/shinigami-777/PoC_CVE-2025-11579'
  checkedAt: '2026-09-26T09:05:32.747Z'
exploitAvailable: true
aliases:
  - GHSA-rwvp-r38j-9rgg
  - GO-2025-4020
ecosystem: go
ingestedAt: '2026-08-07T19:14:17.690Z'
---

## Overview

A memory exhaustion flaw has been discovered in the golang Rar Decode library (github.com/nwaples/rardecode). Affected versions did not limit the size of an archive and so an attacker could provide a crafted archive to a tool or service built on Rar decode which might consume more memory than available. This would lead to a program crash.

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: OpenShift Serverless, Red Hat Advanced Cluster Security 4, Red Hat OpenShift Container Platform 4, Red Hat Trusted Application Pipeline · no fix planned: OpenShift Serverless, Red Hat Advanced Cluster Security 4, Red Hat OpenShift Container Platform 4, Red Hat Trusted Application Pipeline · updated 2026-09-23 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-11579.json)

**github.com/nwaples/rardecode: RarDecode Out Of Memory Crash** — rated Moderate by Red Hat. Released 2025-10-10, updated 2026-09-23.

Affected:

- OpenShift Serverless
- Red Hat Advanced Cluster Security 4
- Red Hat OpenShift Container Platform 4
- Red Hat Trusted Application Pipeline

No fix planned:

- OpenShift Serverless
- Red Hat Advanced Cluster Security 4
- Red Hat OpenShift Container Platform 4
- Red Hat Trusted Application Pipeline

## Remediation

Fix deferred

Workarounds / mitigations:

- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

## Package advisory (CVE-2025-11579)

Affected packages:

- `github.com/nwaples/rardecode/v2 < 2.2.0`
- `github.com/nwaples/rardecode <= 1.1.3`

Patched in:

- `github.com/nwaples/rardecode/v2 2.2.0`

Source: https://osv.dev/vulnerability/GHSA-rwvp-r38j-9rgg
