CVE-2025-32949

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Apr 15, 2025
CWE ID 409

Summary

CVE-2025-32949 is a vulnerability that affects PeerTube, an open-source video hosting platform. This issue allows any authenticated user to cause a serious disk space issue by extracting a maliciously crafted Zip archive, also known as a Zip Bomb. When PeerTube's User Import feature is enabled (the default setting), any registered user can upload such archives. The underlying cause is PeerTube's use of the yauzl library, which lacks protection against Zip Bombs. Consequently, when the platform attempts to extract an affected archive, it consumes excessive disk space, potentially leading to resource exhaustion.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share