Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-7180 | Redlib is an alternative private front-end to Reddit. A vulnerability has been identified in Redlib where an attacker can cause a denial-of-service (DOS) condition by submitting a specially crafted base2048-encoded DEFLATE decompression bomb to the restore_preferences form. This leads to excessive memory consumption and potential system instability, which can be exploited to disrupt Redlib instances. This vulnerability is fixed in 0.36.0. |
Github GHSA |
GHSA-g8vq-v3mg-7mrg | Redlib allows a Denial of Service via DEFLATE Decompression Bomb in restore_preferences Form |
Tue, 03 Feb 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redlib
Redlib redlib |
|
| CPEs | cpe:2.3:a:redlib:redlib:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Redlib
Redlib redlib |
|
| Metrics |
cvssV3_1
|
Thu, 20 Mar 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Mar 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Redlib is an alternative private front-end to Reddit. A vulnerability has been identified in Redlib where an attacker can cause a denial-of-service (DOS) condition by submitting a specially crafted base2048-encoded DEFLATE decompression bomb to the restore_preferences form. This leads to excessive memory consumption and potential system instability, which can be exploited to disrupt Redlib instances. This vulnerability is fixed in 0.36.0. | |
| Title | Redlib allows a Denial of Service via DEFLATE Decompression Bomb in restore_preferences Form | |
| Weaknesses | CWE-400 CWE-502 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-03-20T19:19:50.110Z
Reserved: 2025-03-17T12:41:42.566Z
Link: CVE-2025-30160
Updated: 2025-03-20T19:19:46.648Z
Status : Analyzed
Published: 2025-03-20T19:15:38.383
Modified: 2026-02-03T16:47:39.357
Link: CVE-2025-30160
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA