Vulnerability record · CVE-2025-65637 · published 4 December 2025
CVE-2025-65637: Turbopuffer logrus uncontrolled resource consumption vulnerability
Turbopuffer · Logrus
A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line payload larger than 64KB without newline characters. Due to limitations in the internal bufio.Scanner, the read fails with "token too long" and the writer pipe is closed, leaving Writer() unusable and causing application unavailability (DoS). This affects versions < 1.8.3, 1.9.0, and 1.9.2. The issue is fixed in 1.8.3, 1.9.1, and 1.9.3+, where the input is chunked and the writer continues to function even if an error is logged.
Description
A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line payload larger than 64KB without newline characters. Due to limitations in the internal bufio.Scanner, the read fails with "token too long" and the writer pipe is closed, leaving Writer() unusable and causing application unavailability (DoS). This affects versions < 1.8.3, 1.9.0, and 1.9.2. The issue is fixed in 1.8.3, 1.9.1, and 1.9.3+, where the input is chunked and the writer continues to function even if an error is logged.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/mjuanxd/logrus-dos-poc | ExploitThird Party Advisory |
| https://github.com/mjuanxd/logrus-dos-poc/blob/main/README.md | ExploitThird Party Advisory |
| https://github.com/sirupsen/logrus/issues/1370 | ExploitIssue TrackingPatch |
| https://github.com/sirupsen/logrus/pull/1376 | Issue TrackingPatch |
| https://github.com/sirupsen/logrus/releases/tag/v1.8.3 | Release Notes |
| https://github.com/sirupsen/logrus/releases/tag/v1.9.1 | Release Notes |
| https://github.com/sirupsen/logrus/releases/tag/v1.9.3 | Release Notes |
| https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMSIRUPSENLOGRUS-5564391 | ExploitThird Party Advisory |
Track CVE-2025-65637 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-65637), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.