CVE-2025-11579: rardecode: DoS risk due to unrestricted RAR dictionary sizes
(updated )
rardecode versions <= 2.1.1 fail to restrict the dictionary size when reading large RAR dictionary sizes, which allows an attacker to provide a specially crafted RAR file and cause Denial of Service via an Out Of Memory Crash.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-11579 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →