CVE-2025-65637

EUVD-2025-201258
A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line payload larger than 64KB without newline characters. Due to limitations in the internal bufio.Scanner, the read fails with "token too long" and the writer pipe is closed, leaving Writer() unusable and causing application unavailability (DoS). This affects versions < 1.8.3, 1.9.0, and 1.9.2. The issue is fixed in 1.8.3, 1.9.1, and 1.9.3+, where the input is chunked and the writer continues to function even if an error is logged.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 44%
Affected Products (NVD)
VendorProductVersion
turbopufferlogrus
𝑥
< 1.8.3
turbopufferlogrus
1.9.0
turbopufferlogrus
1.9.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
golang-logrus
bookworm
no-dsa
bullseye
postponed
forky
1.9.3-1
fixed
sid
1.9.3-2
fixed
trixie
no-dsa
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
osbuild-composer
RHEL 8.6 AUS
0:46.3-5.el8_6
fixed
RHEL 8.6 E4S
0:46.3-5.el8_6
fixed
RHEL 8.6 TUS
0:46.3-5.el8_6
fixed
RHEL 8.8 E4S
0:75-6.el8_8
fixed
RHEL 8.8 TUS
0:75-6.el8_8
fixed
osbuild-composer-core
RHEL 8.6 AUS
0:46.3-5.el8_6
fixed
RHEL 8.6 E4S
0:46.3-5.el8_6
fixed
RHEL 8.6 TUS
0:46.3-5.el8_6
fixed
RHEL 8.8 E4S
0:75-6.el8_8
fixed
RHEL 8.8 TUS
0:75-6.el8_8
fixed
osbuild-composer-dnf-json
RHEL 8.6 AUS
0:46.3-5.el8_6
fixed
RHEL 8.6 E4S
0:46.3-5.el8_6
fixed
RHEL 8.6 TUS
0:46.3-5.el8_6
fixed
RHEL 8.8 E4S
0:75-6.el8_8
fixed
RHEL 8.8 TUS
0:75-6.el8_8
fixed
osbuild-composer-worker
RHEL 8.6 AUS
0:46.3-5.el8_6
fixed
RHEL 8.6 E4S
0:46.3-5.el8_6
fixed
RHEL 8.6 TUS
0:46.3-5.el8_6
fixed
RHEL 8.8 E4S
0:75-6.el8_8
fixed
RHEL 8.8 TUS
0:75-6.el8_8
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
amazon-ecr-credential-helper
Amazon Linux 2023
0:0.11.0-2.amzn2023
fixed
ecs-init
Amazon Linux 2023
0:1.82.2-1.amzn2023
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
cert-manager
CBL-Mariner 2.0
0:1.11.2-25.cm2
fixed
cf-cli
CBL-Mariner 2.0
0:8.4.0-26.cm2
fixed
cni-plugins
Azure Linux 3.0
0:1.4.0-4.azl3
fixed
CBL-Mariner 2.0
0:1.3.0-10.cm2
fixed
containerized-data-importer
Azure Linux 3.0
0:1.57.0-18.azl3
fixed
CBL-Mariner 2.0
0:1.55.0-27.cm2
fixed
cri-o
CBL-Mariner 2.0
0:1.22.3-18.cm2
fixed
dcos-cli
Azure Linux 3.0
0:1.2.0-20.azl3
fixed
CBL-Mariner 2.0
0:1.2.0-23.cm2
fixed
flannel
Azure Linux 3.0
0:0.24.2-22.azl3
fixed
CBL-Mariner 2.0
0:0.14.0-27.cm2
fixed
influxdb
Azure Linux 3.0
0:2.7.5-9.azl3
fixed
CBL-Mariner 2.0
0:2.6.1-25.cm2
fixed
jx
CBL-Mariner 2.0
0:3.2.236-24.cm2
fixed
kata-containers
Azure Linux 3.0
0:3.19.1.kata2-5.azl3
fixed
kube-vip-cloud-provider
CBL-Mariner 2.0
0:0.0.2-24.cm2
fixed
kubernetes
Azure Linux 3.0
0:1.30.10-18.azl3
fixed
CBL-Mariner 2.0
0:0.0.0.cm2
fixed
kubevirt
CBL-Mariner 2.0
0:0.59.0-32.cm2
fixed
local-path-provisioner
CBL-Mariner 2.0
0:0.0.21-20.cm2
fixed
moby-buildx
CBL-Mariner 2.0
0:0.7.1-27.cm2
fixed
moby-compose
CBL-Mariner 2.0
0:2.17.3-13.cm2
fixed
prometheus
CBL-Mariner 2.0
0:2.37.9-6.cm2
fixed