7.5

CVE-2025-32947

Exploit

PeerTube ActivityPub Crawl Infinite Loop DoS

This vulnerability allows any attacker to cause the PeerTube server to stop responding to requests due to an infinite loop in the "inbox" endpoint when receiving crafted ActivityPub activities.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
FramasoftPeertube Version < 7.1.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.63% 0.453
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
reefs@jfrog.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

https://github.com/Chocobozzz/PeerTube/releases/tag/v7.1.1
Release Notes
https://research.jfrog.com/vulnerabilities/peertube-activitypub-crawl-dos/
Third Party Advisory
Exploit
https://github.com/Chocobozzz/PeerTube/commit/76226d85685220db1495025300eca784d0336f7d
Patch