Vulnerability Report: GO-2025-4188
- CVE-2025-65637, GHSA-4f99-4q7p-p3gh
- Affects: github.com/sirupsen/logrus
- Published: Dec 15, 2025
- Modified: Jan 20, 2026
Logrus is vulnerable to DoS when using Entry.writerScanner in github.com/sirupsen/logrus
For detailed information about this vulnerability, visit https://github.com/advisories/GHSA-4f99-4q7p-p3gh.
Affected Packages
-
PathGo VersionsSymbols
-
before v1.8.3, from v1.9.0 before v1.9.1, from v1.9.2 before v1.9.3
Aliases
References
- https://github.com/advisories/GHSA-4f99-4q7p-p3gh
- https://github.com/sirupsen/logrus/commit/6acd903758687c4a3db3c11701e6c414fcf1c1f7
- https://github.com/sirupsen/logrus/pull/1376
- https://github.com/sirupsen/logrus/issues/1370
- https://github.com/mjuanxd/logrus-dos-poc
- https://github.com/mjuanxd/logrus-dos-poc/blob/main/README.md
- https://github.com/sirupsen/logrus/releases/tag/v1.8.3
- https://github.com/sirupsen/logrus/releases/tag/v1.9.1
- https://github.com/sirupsen/logrus/releases/tag/v1.9.3
- https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMSIRUPSENLOGRUS-5564391
- https://vuln.go.dev/ID/GO-2025-4188.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.