This vulnerability allows any attacker to cause the PeerTube server to stop responding to requests due to an infinite loop in the "inbox" endpoint when receiving crafted ActivityPub activities.
References
| Link | Resource |
|---|---|
| https://github.com/Chocobozzz/PeerTube/commit/76226d85685220db1495025300eca784d0336f7d | Patch |
| https://github.com/Chocobozzz/PeerTube/releases/tag/v7.1.1 | Release Notes |
| https://research.jfrog.com/vulnerabilities/peertube-activitypub-crawl-dos/ | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2025-04-15 15:16
Updated : 2025-10-21 16:30
NVD link : CVE-2025-32947
Mitre link : CVE-2025-32947
CVE.ORG link : CVE-2025-32947
JSON object : View
Products Affected
framasoft
- peertube
CWE
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
