← Vulnerability feed

Vulnerability record · CVE-2025-27911 · published 11 March 2025

CVE-2025-27911: Datalust seq allocation without limits vulnerability

Datalust · Seq

An issue was discovered in Datalust Seq before 2024.3.13545. Expansion of identifiers in message templates can be used to bypass the system "Event body limit bytes" setting, leading to increased resource consumption. With sufficiently large events, there can be disk space exhaustion (if saved to disk) or a termination of the server process with an out-of-memory error.

6.5 CVSS 3.1 Medium EPSS 0.43% · top 65.5% CWE-770 · Allocation without limits
6.5CVSS 3.1 base score
0.43%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An issue was discovered in Datalust Seq before 2024.3.13545. Expansion of identifiers in message templates can be used to bypass the system "Event body limit bytes" setting, leading to increased resource consumption. With sufficiently large events, there can be disk space exhaustion (if saved to disk) or a termination of the server process with an out-of-memory error.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://datalust.co/seq Product
https://github.com/datalust/seq-tickets/issues/2365 Issue TrackingVendor Advisory

Track CVE-2025-27911 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-8096Datalust Seq authentication bypass via settings API grants admin accessDatalust Seq before 4.2.605 allows an unauthenticated attacker to disable authentication by sending a PUT request to api/settings/setting-isauthentic…EPSS 48%analysed9.1CVE-2024-29866Datalust seq improper access control vulnerabilityDatalust Seq before 2023.4.11151 and 2024 before 2024.1.11146 has Incorrect Access Control because a Project Owner or Organization Owner can escalate…EPSS 0.69%8.8CVE-2025-27912Datalust seq cross-site request forgery vulnerabilityAn issue was discovered in Datalust Seq before 2024.3.13545. Missing Content-Type validation can lead to CSRF when (1) Entra ID or OpenID Connect aut…EPSS 0.19%6.5CVE-2024-58102Datalust seq vulnerabilityAn issue was discovered in Datalust Seq before 2024.3.13545. An insecure default parsing depth limit allows stack consumption when parsing user-suppl…EPSS 0.35%6.5CVE-2021-41329Datalust seq vulnerabilityDatalust Seq before 2021.2.6259 allows users (with view filters applied to their accounts) to see query results not constrained by their view filter.…EPSS 0.99%4.9CVE-2023-38195Datalust seq vulnerabilityDatalust Seq before 2023.2.9489 allows insertion of sensitive information into an externally accessible file or directory. This is exploitable only w…EPSS 0.52%8.6CVE-2020-3569Cisco IOS XR DVMRP IGMP packet handling memory exhaustionCisco IOS XR Software mishandles IGMP packets in its Distance Vector Multicast Routing Protocol (DVMRP) feature, allowing crafted traffic to crash th…KEVEPSS 3.3%analysed8.6CVE-2020-3566Cisco IOS XR DVMRP IGMP queue flaw causes memory exhaustionCisco IOS XR Software mishandles queue management for IGMP packets in its DVMRP feature, allowing uncontrolled memory consumption. An unauthenticated…KEVEPSS 3.7%analysed

Source: NIST National Vulnerability Database (record CVE-2025-27911), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.