VDB
GO-2025-4188
GO-2025-4188
PUBLISHED
CVSS 8.699999809265137 HIGH
Logrus is vulnerable to DoS when using Entry.writerScanner in github.com/sirupsen/logrus
Risk Scores
CVSS 4.0
8.699999809265137
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| chainguard | docker-credential-gcr-fips | 0, 0, 0 |
| chainguard | src-fingerprint | 0, 0, 0 |
| chainguard | neuvector-dbgen-fips | 0, 0, 0 |
| chainguard | docker-credential-gcr | 0, 0, 0 |
| chainguard | src-fingerprint-fips | 0, 0, 0 |
| chainguard | terraform-provider-google | 0, 0, 0 |
| chainguard | kpt | 0, 0, 0 |
| wolfi | hello-world-golang | 0, 0, 0 |
| chainguard | kubeflow | 0, 0, 0 |
| chainguard | aws-flb-kinesis-fips | 0, 0, 0 |
| chainguard | kubernetes-event-exporter-fips | 0, 0, 0 |
| chainguard | gostatsd | 0, 0, 0 |
| chainguard | stakater-reloader-0.0.119 | 0, 0, 0 |
| chainguard | prometheus-beat-exporter | 0, 0, 0 |
| chainguard | php-fpm_exporter | 0, 0, 0 |
| chainguard | hello-world-golang | 0, 0, 0 |
| chainguard | go-discover | 0, 0, 0 |
| wolfi | smokescreen | 0, 0, 0 |
| chainguard | smokescreen | 0, 0, 0 |
| chainguard | consul-fips-1.21 | 0, 0, 0 |
…and 43 more
Timeline
- Dec 15, 2025 CVE Published
- Feb 4, 2026 CVE Updated
References
- https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMSIRUPSENLOGRUS-5564391 url
- https://github.com/advisories/GHSA-4f99-4q7p-p3gh advisory
- https://github.com/mjuanxd/logrus-dos-poc url
- https://github.com/sirupsen/logrus/commit/6acd903758687c4a3db3c11701e6c414fcf1c1f7 fix
- https://github.com/sirupsen/logrus/issues/1370 discussion
- https://github.com/mjuanxd/logrus-dos-poc/blob/main/README.md exploit
- https://github.com/sirupsen/logrus/pull/1376 fix
- https://github.com/sirupsen/logrus/releases/tag/v1.8.3 fix
- https://github.com/sirupsen/logrus/releases/tag/v1.9.1 fix
- https://github.com/sirupsen/logrus/releases/tag/v1.9.3 fix