CVE-2025-32944

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Apr 15, 2025
CWE ID 248

Summary

CVE-2025-32944 is a vulnerability affecting PeerTube servers that enables any authenticated user to cause the system to crash persistently. This issue arises when the yauzl library, used by PeerTube for reading archives, encounters an illegal filename during user import. The uncaught exception resulting from this encounter triggers an infinite loop of crashes upon startup. By default, user import is enabled in PeerTube, making this vulnerability potentially impactful for a large number of installations.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share