This vulnerability allows any attacker to cause the PeerTube server to stop responding to requests due to an infinite loop in the "inbox" endpoint when receiving crafted ActivityPub activities.
References
| Link | Resource |
|---|---|
| https://github.com/Chocobozzz/PeerTube/commit/76226d85685220db1495025300eca784d0336f7d | Patch |
| https://github.com/Chocobozzz/PeerTube/releases/tag/v7.1.1 | Release Notes |
| https://research.jfrog.com/vulnerabilities/peertube-activitypub-crawl-dos/ | Exploit Third Party Advisory |
Configurations
History
21 Oct 2025, 16:30
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:framasoft:peertube:*:*:*:*:*:*:*:* | |
| References | () https://github.com/Chocobozzz/PeerTube/commit/76226d85685220db1495025300eca784d0336f7d - Patch | |
| References | () https://github.com/Chocobozzz/PeerTube/releases/tag/v7.1.1 - Release Notes | |
| References | () https://research.jfrog.com/vulnerabilities/peertube-activitypub-crawl-dos/ - Exploit, Third Party Advisory | |
| First Time |
Framasoft
Framasoft peertube |
20 Aug 2025, 09:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| Summary |
|
15 Apr 2025, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-04-15 15:16
Updated : 2025-10-21 16:30
NVD link : CVE-2025-32947
Mitre link : CVE-2025-32947
CVE.ORG link : CVE-2025-32947
JSON object : View
Products Affected
framasoft
- peertube
CWE
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
