Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-64508

25
FAUCET Score

CVE-2025-64508 describes a Denial of Service vulnerability in Bugsink, a self-hosted error tracking tool, affecting versions prior to 2.0.5. Attackers can exploit this by sending specially crafted, highly compressed brotli streams ("brotli bombs") to the server, leading to memory exhaustion during decompression. This unauthenticated attack has a high severity CVSS score of 7.5, indicating a significant impact on availability. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
BugsinkBugsink
< 2.0.5CNA affected

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.46%
Probability of exploitation in next 30 days
EPSS Percentile
37.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0046 is in the 16th percentile among its peer group of 51,553 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

pippatch availablevia ghsa
Product: bugsinkFixed in: 2.0.5

Vendor Advisories (1)

pipGHSA-fc2v-vcwj-269vhigh

Bugsink is vulnerable to unauthenticated remote DoS via crafted Brotli input

Nov 13, 2025

References

github.com / bugsink/bugsink/commit/3f65544aab3ad5303d97009136640de97b0676a5
github.com / bugsink/bugsink/pull/266
github.com / bugsink/bugsink/security/advisories/GHSA-fc2v-vcwj-269v
github.com / google/brotli/commit/67d78bc41db1a0d03f2e763497748f2f69946627
github.com / google/brotli/issues/1327
github.com / google/brotli/issues/1375
github.com / google/brotli/pull/1234
github.com / google/brotli/releases/tag/v1.2.0