CVE-2025-27911
Datalust Seq vulnerability analysis and mitigation

Overview

A vulnerability was discovered in Datalust Seq versions prior to 2024.3.13545. The vulnerability (CVE-2025-27911) involves the expansion of identifiers in message templates that can bypass the system's "Event body limit bytes" setting. This was initially reported as high-severity but was later downgraded to medium severity with a CVSS 3.1 score of 6.0. The vulnerability was discovered through Datalust's internal security processes and disclosed on February 17, 2025 (Seq Tickets).

Technical details

The vulnerability exists in the message template processing mechanism of Seq, where the expansion of identifiers can circumvent the configured event body size limitations. This bypass leads to increased resource consumption beyond intended limits. The vulnerability has been assigned a CVSS 3.1 vector string of AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:F/RL:O/RC:C, indicating network accessibility, low attack complexity, and high availability impact (Seq Tickets).

Impact

When exploited, this vulnerability can result in increased resource consumption leading to either disk space exhaustion (if events are saved to disk) or termination of the server process due to out-of-memory errors. The impact is particularly severe because ingested events are persisted, meaning availability issues may continue even after system restart when malicious events are accessed during queries or indexing operations (Seq Tickets).

Mitigation and workarounds

The vulnerability has been patched in Seq version 2024.3.13545. All Seq customers are advised to update to this version or later builds as soon as possible. The fixed version is available for download from the official website or via Docker image datalust/seq:2024.3.13545 (Seq Tickets, Datalust).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management