CVE-2025-65637Patch(turbopuffer / logrus)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch turbopuffer logrus systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line payload larger than 64KB without newline characters. Due to limitations in the internal bufio.Scanner, the read fails with "token too long" and the writer pipe is closed, leaving Writer() unusable and causing application unavailability (DoS). This affects versions < 1.8.3, 1.9.0, and 1.9.2. The issue is fixed in 1.8.3, 1.9.1, and 1.9.3+, where the input is chunked and the writer continues to function even if an error is logged.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • logrus

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • 2 total mentions across 1 day

Affected systems

Products
logrus

2 versions affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-19: 2Patch / Workaround · 2026-02-19: 2Technical Details · 2026-02-19: 202-19
Signal classification1 categories
Patch
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🔧 #Fedora 42 Security Corner A critical patch for fvwm3 just dropped (FEDORA-2026-439af2cc95) addressing CVE-2025-65637. This is a nasty one: a remote DoS in the Logrus library. Read more: 👉 https://tinyurl.com/3xt2t8hr #Security https://t.co/QG6H0KUVN2

    Post summary

    The tweet announces a critical patch for Fedora 42 addressing CVE-2025-65637, describing the vulnerability as a remote DoS in the Logrus library. No PoC, exploit code, or active exploitation claims are present.

    0000058
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Critical security update for #Fedora users! A new patch for Fvwm3 (CVE-2025-65637) fixes a high-severity Denial-of-Service flaw in the logrus logging library. Read more:👉 https://tinyurl.com/mu6ftvdx #Security https://t.co/fJ4t59em9j

    Post summary

    The tweet announces a Fedora patch for CVE-2025-65637, detailing a high‑severity DoS flaw in the logrus logging library, and directs users to the vendor advisory.

    0000059
    1.3K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appturbopufferlogrus-go-
Appturbopufferlogrus1.9.0go-
Appturbopufferlogrus1.9.2go-

Explore more