Skip to content
VictoriaMetricsGHSA-66jq-2c23-2xh5

VictoriaMetrics' Snappy Decoder DoS Vulnerability is Causing OOM

Low2.7CVE-2025-65942 · Published Nov 25, 2025 · updated Sep 10, 2026

### Impact Affected versions are vulnerable to DoS attacks because the snappy decoder ignored VictoriaMetrics request size limits allowing malformed blocks to trigger excessive memory use. This could lead to OOM errors and service instability. The fix enforces block-size checks based on MaxRequest limits. ### Patches Versions 1.129.1, 1.122.8, 1.110.23 ### Resources - https://github.com/VictoriaMetrics/VictoriaMetrics/releases/tag/v1.129.1 - https://github.com/VictoriaMetrics/VictoriaMetrics/releases/tag/v1.122.8 - https://github.com/VictoriaMetrics/VictoriaMetrics/releases/tag/v1.110.23 ### Note VictoriaMetrics' security model assumes its APIs are properly secured (e.g. via access control flags or a firewall); this advisory addresses malicious input that should not be possible under a [correctly secured](https://docs.victoriametrics.com/victoriametrics/single-server-victoriametrics/#security) deployment.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/VictoriaMetrics/VictoriaMetrics
Go
>= 1.123.0, < 1.129.11.129.1
>= 1.111.0, < 1.122.81.122.8
>= 1.0.0, < 1.110.231.110.23
Details and references

More VictoriaMetrics advisories

All VictoriaMetrics
Advisory
VictoriaMetrics vmrestore: Path traversal via crafted backup part names escapes restore root
Medium6.8Sep 3

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.