Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.6, a specially crafted Brotli-compressed envelope can cause Bugsink to spend excessive CPU time in decompression, leading to denial of service. This can be done if the DSN is known, which it is in many common setups (JavaScript, Mobile Apps). The issue is patched in Bugsink 2.0.6. The vulnerability is similar to, but distinct from, another brotli-related problem in Bugsink, GHSA-fc2v-vcwj-269v/CVE-2025-64508.
History

Mon, 10 Nov 2025 22:00:00 +0000

Type Values Removed Values Added
Description Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.6, a specially crafted Brotli-compressed envelope can cause Bugsink to spend excessive CPU time in decompression, leading to denial of service. This can be done if the DSN is known, which it is in many common setups (JavaScript, Mobile Apps). The issue is patched in Bugsink 2.0.6. The vulnerability is similar to, but distinct from, another brotli-related problem in Bugsink, GHSA-fc2v-vcwj-269v/CVE-2025-64508.
Title Bugsink vulnerable to unauthenticated remote DoS via crafted Brotli input (via CPU)
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-11-10T21:46:11.117Z

Updated: 2025-11-10T21:46:11.117Z

Reserved: 2025-11-05T21:15:39.399Z

Link: CVE-2025-64509

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-11-10T22:15:39.873

Modified: 2025-11-10T22:15:39.873

Link: CVE-2025-64509

cve-icon Redhat

No data.