{"id":"CVE-2025-30160","aliases":["GHSA-g8vq-v3mg-7mrg"],"url":"https://o3.security/vulnerability/CVE-2025-30160","summary":"Redlib allows a Denial of Service via DEFLATE Decompression Bomb in restore_preferences Form","details":"Redlib is an alternative private front-end to Reddit. A vulnerability has been identified in Redlib where an attacker can cause a denial-of-service (DOS) condition by submitting a specially crafted base2048-encoded DEFLATE decompression bomb to the restore_preferences form. This leads to excessive memory consumption and potential system instability, which can be exploited to disrupt Redlib instances. This vulnerability is fixed in 0.36.0.","published":"2025-03-20T18:09:48.763Z","modified":"2026-08-12T03:51:41.435521700Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"redlib","fixedVersion":"0.36.0"}],"fix":{"url":"https://github.com/redlib-org/redlib/commit/15147cea8e42f6569a11603d661d71122f6a02dc","label":"redlib-org/redlib@15147ce"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/30xxx/CVE-2025-30160.json"},{"type":"ADVISORY","url":"https://github.com/redlib-org/redlib/security/advisories/GHSA-g8vq-v3mg-7mrg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-30160"},{"type":"FIX","url":"https://github.com/redlib-org/redlib/commit/15147cea8e42f6569a11603d661d71122f6a02dc"},{"type":"FIX","url":"https://github.com/redlib-org/redlib/commit/2e95e1fc6e2064ccfae87964b4860bda55eddb9a"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:41.435521700Z"}}