VictoriaMetrics' Snappy Decoder DoS Vulnerability is Causing OOM in github.com/VictoriaMetrics/VictoriaMetrics
{
"review_status": "REVIEWED",
"url": "https://pkg.go.dev/vuln/GO-2025-4161"
}{
"custom_ranges": [
{
"events": [
{
"introduced": "1.0.0"
}
],
"type": "ECOSYSTEM"
}
],
"imports": [
{
"path": "github.com/VictoriaMetrics/VictoriaMetrics/lib/protoparser/promremotewrite/stream",
"symbols": [
"Parse"
]
},
{
"path": "github.com/VictoriaMetrics/VictoriaMetrics/lib/protoparser/protoparserutil",
"symbols": [
"GetUncompressedReader",
"ReadUncompressedData",
"snappyReader.Reset"
]
}
]
}