Vulnerability Details CVE-2025-27911
An issue was discovered in Datalust Seq before 2024.3.13545. Expansion of identifiers in message templates can be used to bypass the system "Event body limit bytes" setting, leading to increased resource consumption. With sufficiently large events, there can be disk space exhaustion (if saved to disk) or a termination of the server process with an out-of-memory error.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 33.0%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2025-27911
-
cpe:2.3:a:datalust:seq:1.3.
-
cpe:2.3:a:datalust:seq:1.3.10
-
cpe:2.3:a:datalust:seq:1.3.11
-
cpe:2.3:a:datalust:seq:1.3.9
-
cpe:2.3:a:datalust:seq:1.4.10
-
cpe:2.3:a:datalust:seq:1.4.11
-
cpe:2.3:a:datalust:seq:1.4.12
-
cpe:2.3:a:datalust:seq:1.4.6
-
cpe:2.3:a:datalust:seq:1.4.7
-
cpe:2.3:a:datalust:seq:1.4.8
-
cpe:2.3:a:datalust:seq:1.4.9
-
cpe:2.3:a:datalust:seq:1.5.16
-
cpe:2.3:a:datalust:seq:1.5.17
-
cpe:2.3:a:datalust:seq:1.5.18
-
cpe:2.3:a:datalust:seq:1.5.19
-
cpe:2.3:a:datalust:seq:1.6.10
-
cpe:2.3:a:datalust:seq:1.6.11
-
cpe:2.3:a:datalust:seq:1.6.12
-
cpe:2.3:a:datalust:seq:1.6.13
-
cpe:2.3:a:datalust:seq:1.6.4
-
cpe:2.3:a:datalust:seq:1.6.5
-
cpe:2.3:a:datalust:seq:1.6.6
-
cpe:2.3:a:datalust:seq:1.6.7
-
cpe:2.3:a:datalust:seq:1.6.8
-
cpe:2.3:a:datalust:seq:1.6.9
-
cpe:2.3:a:datalust:seq:2.0.19
-
cpe:2.3:a:datalust:seq:2.1.21
-
cpe:2.3:a:datalust:seq:2.1.22
-
cpe:2.3:a:datalust:seq:2.2.8
-
cpe:2.3:a:datalust:seq:2.3.3
-
cpe:2.3:a:datalust:seq:2.3.4
-
cpe:2.3:a:datalust:seq:2.4.2
-
cpe:2.3:a:datalust:seq:2020.1.4212
-
cpe:2.3:a:datalust:seq:2020.1.4235
-
cpe:2.3:a:datalust:seq:2020.1.4292
-
cpe:2.3:a:datalust:seq:2020.2.4591
-
cpe:2.3:a:datalust:seq:2020.2.4593
-
cpe:2.3:a:datalust:seq:2020.3.4761
-
cpe:2.3:a:datalust:seq:2020.4.5070
-
cpe:2.3:a:datalust:seq:2020.4.5089
-
cpe:2.3:a:datalust:seq:2020.4.5119
-
cpe:2.3:a:datalust:seq:2020.5.5163
-
cpe:2.3:a:datalust:seq:2021.1.5282
-
cpe:2.3:a:datalust:seq:2021.1.5307
-
cpe:2.3:a:datalust:seq:2021.1.5425
-
cpe:2.3:a:datalust:seq:2021.2.5495
-
cpe:2.3:a:datalust:seq:2021.2.5595
-
cpe:2.3:a:datalust:seq:2021.2.5647
-
cpe:2.3:a:datalust:seq:2021.2.6259
-
cpe:2.3:a:datalust:seq:2021.2.6288
-
cpe:2.3:a:datalust:seq:2021.2.6459
-
cpe:2.3:a:datalust:seq:2021.3.6651
-
cpe:2.3:a:datalust:seq:2021.3.6660
-
cpe:2.3:a:datalust:seq:2021.3.6681
-
cpe:2.3:a:datalust:seq:2021.3.6800
-
cpe:2.3:a:datalust:seq:2021.4.6986
-
cpe:2.3:a:datalust:seq:2021.4.7192
-
cpe:2.3:a:datalust:seq:2022.1.7378
-
cpe:2.3:a:datalust:seq:2022.1.7449
-
cpe:2.3:a:datalust:seq:2022.1.7647
-
cpe:2.3:a:datalust:seq:2022.1.7929
-
cpe:2.3:a:datalust:seq:2023.1.8829
-
cpe:2.3:a:datalust:seq:2023.1.8847
-
cpe:2.3:a:datalust:seq:2023.1.8876
-
cpe:2.3:a:datalust:seq:2023.1.8899
-
cpe:2.3:a:datalust:seq:2023.1.8948
-
cpe:2.3:a:datalust:seq:2023.1.8991
-
cpe:2.3:a:datalust:seq:2023.1.9101
-
cpe:2.3:a:datalust:seq:2023.1.9133
-
cpe:2.3:a:datalust:seq:2023.1.9162
-
cpe:2.3:a:datalust:seq:2023.1.9229
-
cpe:2.3:a:datalust:seq:2023.2.9372
-
cpe:2.3:a:datalust:seq:2023.2.9489
-
cpe:2.3:a:datalust:seq:2023.3.9558
-
cpe:2.3:a:datalust:seq:2023.3.9661
-
cpe:2.3:a:datalust:seq:2023.4.11151
-
cpe:2.3:a:datalust:seq:2024
-
cpe:2.3:a:datalust:seq:2024.1.10981
-
cpe:2.3:a:datalust:seq:2024.1.11001
-
cpe:2.3:a:datalust:seq:2024.1.11028
-
cpe:2.3:a:datalust:seq:2024.1.11146
-
cpe:2.3:a:datalust:seq:2024.2.11240
-
cpe:2.3:a:datalust:seq:2024.2.11282
-
cpe:2.3:a:datalust:seq:2024.2.11456
-
cpe:2.3:a:datalust:seq:2024.2.12023
-
cpe:2.3:a:datalust:seq:2024.3.11510
-
cpe:2.3:a:datalust:seq:2024.3.11547
-
cpe:2.3:a:datalust:seq:2024.3.11914
-
cpe:2.3:a:datalust:seq:2024.3.12021
-
cpe:2.3:a:datalust:seq:2024.3.12250
-
cpe:2.3:a:datalust:seq:2024.3.12680
-
cpe:2.3:a:datalust:seq:2024.3.13080
-
cpe:2.3:a:datalust:seq:2024.3.13181
-
cpe:2.3:a:datalust:seq:3.0.30
-
cpe:2.3:a:datalust:seq:3.1.16
-
cpe:2.3:a:datalust:seq:3.1.17
-
cpe:2.3:a:datalust:seq:3.2.16
-
cpe:2.3:a:datalust:seq:3.3.20
-
cpe:2.3:a:datalust:seq:3.3.21
-
cpe:2.3:a:datalust:seq:3.3.22
-
cpe:2.3:a:datalust:seq:3.3.23
-
cpe:2.3:a:datalust:seq:3.4.17
-
cpe:2.3:a:datalust:seq:3.4.18
-
cpe:2.3:a:datalust:seq:3.4.20
-
cpe:2.3:a:datalust:seq:4.0.58
-
cpe:2.3:a:datalust:seq:4.0.60
-
cpe:2.3:a:datalust:seq:4.1.14
-
cpe:2.3:a:datalust:seq:4.1.16
-
cpe:2.3:a:datalust:seq:4.1.17
-
cpe:2.3:a:datalust:seq:4.2.1113
-
cpe:2.3:a:datalust:seq:4.2.470
-
cpe:2.3:a:datalust:seq:4.2.476
-
cpe:2.3:a:datalust:seq:4.2.605
-
cpe:2.3:a:datalust:seq:4.2.717
-
cpe:2.3:a:datalust:seq:4.2.822
-
cpe:2.3:a:datalust:seq:4.2.839
-
cpe:2.3:a:datalust:seq:5.0.2287
-
cpe:2.3:a:datalust:seq:5.0.2296
-
cpe:2.3:a:datalust:seq:5.0.2313
-
cpe:2.3:a:datalust:seq:5.0.2360
-
cpe:2.3:a:datalust:seq:5.0.2375
-
cpe:2.3:a:datalust:seq:5.0.2394
-
cpe:2.3:a:datalust:seq:5.0.2497
-
cpe:2.3:a:datalust:seq:5.0.2787
-
cpe:2.3:a:datalust:seq:5.0.2817
-
cpe:2.3:a:datalust:seq:5.1.2976
-
cpe:2.3:a:datalust:seq:5.1.3000
-
cpe:2.3:a:datalust:seq:5.1.3004
-
cpe:2.3:a:datalust:seq:5.1.3093
-
cpe:2.3:a:datalust:seq:5.1.3118
-
cpe:2.3:a:datalust:seq:5.1.3200
-
cpe:2.3:a:datalust:seq:5.1.3364