{"id":"CVE-2025-69255","summary":"RustFS gRPC GetMetrics deserialization panic enables remote DoS","details":"RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 to 1.0.0-alpha.77, a malformed gRPC GetMetrics request causes get_metrics to unwrap() failed deserialization of metric_type/opts, panicking the handler thread and enabling remote denial of service of the metrics endpoint. This issue has been patched in version 1.0.0-alpha.78.","aliases":["GHSA-gw2x-q739-qhcr"],"modified":"2026-08-12T03:51:31.462412408Z","published":"2026-01-07T20:34:25.282Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-755"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/69xxx/CVE-2025-69255.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/69xxx/CVE-2025-69255.json"},{"type":"ADVISORY","url":"https://github.com/rustfs/rustfs/security/advisories/GHSA-gw2x-q739-qhcr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69255"},{"type":"FIX","url":"https://github.com/rustfs/rustfs/commit/eb33e82b56ed11fd12bb39416359d8d60737dc7a"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/rustfs/rustfs","events":[{"introduced":"b97845fffdae24affedc2e95153da7bf75049a95"},{"fixed":"eb33e82b56ed11fd12bb39416359d8d60737dc7a"}],"database_specific":{"extracted_events":[{"introduced":"1.0.0-alpha.13"},{"fixed":"1.0.0-alpha.78"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["1.0.0-alpha.77","1.0.0-alpha.76","1.0.0-alpha.75","1.0.0-alpha.74","1.0.0-alpha.73","1.0.0-alpha.72","1.0.0-alpha.71","1.0.0-alpha.70","1.0.0-alpha.69","1.0.0-alpha.68","1.0.0-alpha.67","1.0.0-alpha.66","1.0.0-alpha.65","1.0.0-alpha.64","1.0.0-alpha.63","1.0.0-alpha.62","1.0.0-alpha.61","1.0.0-alpha.60","1.0.0-alpha.59","1.0.0-alpha.58","1.0.0-alpha.57","1.0.0-alpha.56","1.0.0-alpha.55","1.0.0-alpha.54","1.0.0-alpha.53","1.0.0-alpha.52","1.0.0-alpha.51","1.0.0-alpha.50","1.0.0-alpha.49","1.0.0-alpha.48","1.0.0-alpha.47","1.0.0-alpha.46","1.0.0-alpha.45","1.0.0-alpha.44","1.0.0-alpha.43","1.0.0-alpha.42","1.0.0-alpha.41","1.0.0-alpha.40","1.0.0-alpha.39","1.0.0-alpha.38","1.0.0-alpha.37","1.0.0-alpha.36","1.0.0-alpha.35","1.0.0-alpha.34","1.0.0-alpha.33","1.0.0-alpha.32","1.0.0-alpha.31","1.0.0-alpha.30","1.0.0-alpha.29","1.0.0-alpha.28","1.0.0-alpha.27","1.0.0-alpha.26","1.0.0-alpha.25","1.0.0-alpha.24","1.0.0-alpha.23","1.0.0-alpha.22","1.0.0-alpha.21","1.0.0-alpha.20","1.0.0-alpha.19","1.0.0-alpha.18","1.0.0-alpha.17","1.0.0-alpha.16","1.0.0-alpha.15","1.0.0-alpha.14","1.0.0-alpha.13"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-69255.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"}]}