PT-2025-46208 · Bugsink · Bugsink

CVE-2025-64509

·

Published

2025-11-10

·

Updated

2026-07-07

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Bugsink versions prior to 2.0.6
Description Bugsink is a self-hosted error tracking tool. A specially crafted Brotli-compressed envelope can cause Bugsink to expend excessive CPU time during decompression, resulting in a denial of service. This is possible if the Data Source Name (DSN) is known, which is common in many configurations like JavaScript and Mobile Apps. This issue is distinct from another Brotli-related problem in Bugsink.
Recommendations Update to Bugsink version 2.0.6 or later.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-64509
GHSA-RRX3-2X4G-MQ2H
PYSEC-2026-1227

Affected Products

Bugsink