Skip to content

Crowdsec 1.8.1 container with CPU spikes every 5min #4670

Description

@bondskin

What happened?

Since running 1.8.1 and enabled bot detection & challenge plus applying the latest rule set today, I am noticing CPU peak every 5min.

Image

Following update was done this morning (plus container restart afterwards):
collections: crowdsecurity/appsec-bot-challenge-good-bots (0.1 -> 0.1), crowdsecurity/appsec-virtual-patching (15.8 -> 15.9), crowdsecurity/base-http-scenarios (1.4 -> 1.4)
appsec-rules: crowdsecurity/vpatch-CVE-2025-40552 (0.1)
appsec-configs: crowdsecurity/appsec-bot-challenge-exclude-ai-crawlers (0.1 -> 0.2), crowdsecurity/appsec-bot-challenge-exclude-search-engines (0.1 -> 0.2), crowdsecurity/appsec-bot-challenge-exclude-social (0.1 -> 0.2)
parsers: crowdsecurity/http-logs (1.3 -> 1.4)
✅ enable
appsec-rules: crowdsecurity/vpatch-CVE-2025-40552
🔄 check & update data files

downloading parsers:crowdsecurity/http-logs
downloading appsec-configs:crowdsecurity/appsec-bot-challenge-exclude-ai-crawlers
downloading https://hub-data.crowdsec.net/whitelists/benign_bots/legit_bots/anthropic.json
downloading https://hub-data.crowdsec.net/whitelists/benign_bots/legit_bots/commoncrawl.json
downloading https://hub-data.crowdsec.net/whitelists/benign_bots/legit_bots/mistralai-index.json
downloading https://hub-data.crowdsec.net/whitelists/benign_bots/legit_bots/mistralai-user.json
downloading https://hub-data.crowdsec.net/whitelists/benign_bots/legit_bots/openai-adsbot.json
downloading https://hub-data.crowdsec.net/whitelists/benign_bots/legit_bots/perplexity-user.json
downloading https://hub-data.crowdsec.net/whitelists/benign_bots/legit_bots/duckassistbot.json
downloading https://hub-data.crowdsec.net/whitelists/benign_bots/legit_bots/youbot.json
downloading appsec-configs:crowdsecurity/appsec-bot-challenge-exclude-search-engines
downloading https://hub-data.crowdsec.net/whitelists/benign_bots/legit_bots/ahrefs.json
downloading https://hub-data.crowdsec.net/whitelists/benign_bots/legit_bots/semrush.json
downloading https://hub-data.crowdsec.net/whitelists/benign_bots/legit_bots/lumar.json
downloading https://hub-data.crowdsec.net/whitelists/benign_bots/legit_bots/seznam.json
downloading https://hub-data.crowdsec.net/whitelists/benign_bots/legit_bots/naver.json
downloading https://hub-data.crowdsec.net/whitelists/benign_bots/legit_bots/internet-archive.json
downloading appsec-configs:crowdsecurity/appsec-bot-challenge-exclude-social
downloading https://hub-data.crowdsec.net/whitelists/benign_bots/legit_bots/linkedin.json
downloading https://hub-data.crowdsec.net/whitelists/benign_bots/legit_bots/flipboard.json
downloading collections:crowdsecurity/appsec-bot-challenge-good-bots
downloading appsec-rules:crowdsecurity/vpatch-CVE-2025-40552
enabling appsec-rules:crowdsecurity/vpatch-CVE-2025-40552
downloading collections:crowdsecurity/appsec-virtual-patching
downloading collections:crowdsecurity/base-http-scenarios

cscli appsec-rules list
───────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────
APPSEC-RULES
───────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────
Name 📦 Status Version Local Path
───────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────
crowdsecurity/appsec-generic-test ✔️ enabled 0.3 /etc/crowdsec/appsec-rules/appsec-generic-test.yaml
crowdsecurity/base-config ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/base-config.yaml
crowdsecurity/crs ✔️ enabled 0.6 /etc/crowdsec/appsec-rules/crs.yaml
crowdsecurity/experimental-no-user-agent ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/experimental-no-user-agent.yaml
crowdsecurity/generic-freemarker-ssti ✔️ enabled 0.4 /etc/crowdsec/appsec-rules/generic-freemarker-ssti.yaml
crowdsecurity/generic-wordpress-uploads-listing ✔️ enabled 0.4 /etc/crowdsec/appsec-rules/generic-wordpress-uploads-listing.yaml
crowdsecurity/generic-wordpress-uploads-php ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/generic-wordpress-uploads-php.yaml
crowdsecurity/vpatch-connectwise-auth-bypass ✔️ enabled 0.4 /etc/crowdsec/appsec-rules/vpatch-connectwise-auth-bypass.yaml
crowdsecurity/vpatch-CVE-2002-1131 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2002-1131.yaml
crowdsecurity/vpatch-CVE-2007-0885 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2007-0885.yaml
crowdsecurity/vpatch-CVE-2014-5181 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2014-5181.yaml
crowdsecurity/vpatch-CVE-2017-9841 ✔️ enabled 0.4 /etc/crowdsec/appsec-rules/vpatch-CVE-2017-9841.yaml
crowdsecurity/vpatch-CVE-2018-1000861 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2018-1000861.yaml
crowdsecurity/vpatch-CVE-2018-10562 ✔️ enabled 0.3 /etc/crowdsec/appsec-rules/vpatch-CVE-2018-10562.yaml
crowdsecurity/vpatch-CVE-2018-11511 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2018-11511.yaml
crowdsecurity/vpatch-CVE-2018-1207 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2018-1207.yaml
crowdsecurity/vpatch-CVE-2018-13317 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2018-13317.yaml
crowdsecurity/vpatch-CVE-2018-13379 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2018-13379.yaml
crowdsecurity/vpatch-CVE-2018-20062 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2018-20062.yaml
crowdsecurity/vpatch-CVE-2019-1003030 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2019-1003030.yaml
crowdsecurity/vpatch-CVE-2019-12989 ✔️ enabled 0.4 /etc/crowdsec/appsec-rules/vpatch-CVE-2019-12989.yaml
crowdsecurity/vpatch-CVE-2019-18935 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2019-18935.yaml
crowdsecurity/vpatch-CVE-2019-18952 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2019-18952.yaml
crowdsecurity/vpatch-CVE-2019-5418 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2019-5418.yaml
crowdsecurity/vpatch-CVE-2019-7276 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2019-7276.yaml
crowdsecurity/vpatch-CVE-2019-9762 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2019-9762.yaml
crowdsecurity/vpatch-CVE-2020-10987 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2020-10987.yaml
crowdsecurity/vpatch-CVE-2020-11738 ✔️ enabled 0.7 /etc/crowdsec/appsec-rules/vpatch-CVE-2020-11738.yaml
crowdsecurity/vpatch-CVE-2020-13640 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2020-13640.yaml
crowdsecurity/vpatch-CVE-2020-17496 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2020-17496.yaml
crowdsecurity/vpatch-CVE-2020-25078 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2020-25078.yaml
crowdsecurity/vpatch-CVE-2020-37123 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2020-37123.yaml
crowdsecurity/vpatch-CVE-2020-5902 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2020-5902.yaml
crowdsecurity/vpatch-CVE-2020-8656 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2020-8656.yaml
crowdsecurity/vpatch-CVE-2020-9054 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2020-9054.yaml
crowdsecurity/vpatch-CVE-2021-22941 ✔️ enabled 0.4 /etc/crowdsec/appsec-rules/vpatch-CVE-2021-22941.yaml
crowdsecurity/vpatch-CVE-2021-25281 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2021-25281.yaml
crowdsecurity/vpatch-CVE-2021-26072 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2021-26072.yaml
crowdsecurity/vpatch-CVE-2021-26086 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2021-26086.yaml
crowdsecurity/vpatch-CVE-2021-26294 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2021-26294.yaml
crowdsecurity/vpatch-CVE-2021-3129 ✔️ enabled 0.5 /etc/crowdsec/appsec-rules/vpatch-CVE-2021-3129.yaml
crowdsecurity/vpatch-CVE-2021-32478 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2021-32478.yaml
crowdsecurity/vpatch-CVE-2021-34427 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2021-34427.yaml
crowdsecurity/vpatch-CVE-2021-43798 ✔️ enabled 0.5 /etc/crowdsec/appsec-rules/vpatch-CVE-2021-43798.yaml
crowdsecurity/vpatch-CVE-2021-44529 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2021-44529.yaml
crowdsecurity/vpatch-CVE-2022-1388 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2022-1388.yaml
crowdsecurity/vpatch-CVE-2022-22954 ✔️ enabled 0.3 /etc/crowdsec/appsec-rules/vpatch-CVE-2022-22954.yaml
crowdsecurity/vpatch-CVE-2022-22965 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2022-22965.yaml
crowdsecurity/vpatch-CVE-2022-24086 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2022-24086.yaml
crowdsecurity/vpatch-CVE-2022-25322 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2022-25322.yaml
crowdsecurity/vpatch-CVE-2022-25488 ✔️ enabled 0.5 /etc/crowdsec/appsec-rules/vpatch-CVE-2022-25488.yaml
crowdsecurity/vpatch-CVE-2022-26134 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2022-26134.yaml
crowdsecurity/vpatch-CVE-2022-27926 ✔️ enabled 0.4 /etc/crowdsec/appsec-rules/vpatch-CVE-2022-27926.yaml
crowdsecurity/vpatch-CVE-2022-31499 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2022-31499.yaml
crowdsecurity/vpatch-CVE-2022-3236 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2022-3236.yaml
crowdsecurity/vpatch-CVE-2022-35914 ✔️ enabled 0.6 /etc/crowdsec/appsec-rules/vpatch-CVE-2022-35914.yaml
crowdsecurity/vpatch-CVE-2022-38627 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2022-38627.yaml
crowdsecurity/vpatch-CVE-2022-41082 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2022-41082.yaml
crowdsecurity/vpatch-CVE-2022-44877 ✔️ enabled 0.3 /etc/crowdsec/appsec-rules/vpatch-CVE-2022-44877.yaml
crowdsecurity/vpatch-CVE-2022-46169 ✔️ enabled 0.6 /etc/crowdsec/appsec-rules/vpatch-CVE-2022-46169.yaml
crowdsecurity/vpatch-CVE-2023-0297 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2023-0297.yaml
crowdsecurity/vpatch-CVE-2023-1389 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2023-1389.yaml
crowdsecurity/vpatch-CVE-2023-20198 ✔️ enabled 0.7 /etc/crowdsec/appsec-rules/vpatch-CVE-2023-20198.yaml
crowdsecurity/vpatch-CVE-2023-22515 ✔️ enabled 0.5 /etc/crowdsec/appsec-rules/vpatch-CVE-2023-22515.yaml
crowdsecurity/vpatch-CVE-2023-22527 ✔️ enabled 0.3 /etc/crowdsec/appsec-rules/vpatch-CVE-2023-22527.yaml
crowdsecurity/vpatch-CVE-2023-23063 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2023-23063.yaml
crowdsecurity/vpatch-CVE-2023-23752 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2023-23752.yaml
crowdsecurity/vpatch-CVE-2023-24000 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2023-24000.yaml
crowdsecurity/vpatch-CVE-2023-24489 ✔️ enabled 0.3 /etc/crowdsec/appsec-rules/vpatch-CVE-2023-24489.yaml
crowdsecurity/vpatch-CVE-2023-28121 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2023-28121.yaml
crowdsecurity/vpatch-CVE-2023-3169 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2023-3169.yaml
crowdsecurity/vpatch-CVE-2023-33617 ✔️ enabled 0.5 /etc/crowdsec/appsec-rules/vpatch-CVE-2023-33617.yaml
crowdsecurity/vpatch-CVE-2023-34362 ✔️ enabled 0.7 /etc/crowdsec/appsec-rules/vpatch-CVE-2023-34362.yaml
crowdsecurity/vpatch-CVE-2023-35078 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2023-35078.yaml
crowdsecurity/vpatch-CVE-2023-35082 ✔️ enabled 0.3 /etc/crowdsec/appsec-rules/vpatch-CVE-2023-35082.yaml
crowdsecurity/vpatch-CVE-2023-3519 ✔️ enabled 0.4 /etc/crowdsec/appsec-rules/vpatch-CVE-2023-3519.yaml
crowdsecurity/vpatch-CVE-2023-35708 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2023-35708.yaml
crowdsecurity/vpatch-CVE-2023-38205 ✔️ enabled 0.4 /etc/crowdsec/appsec-rules/vpatch-CVE-2023-38205.yaml
crowdsecurity/vpatch-CVE-2023-40044 ✔️ enabled 0.4 /etc/crowdsec/appsec-rules/vpatch-CVE-2023-40044.yaml
crowdsecurity/vpatch-CVE-2023-42793 ✔️ enabled 0.4 /etc/crowdsec/appsec-rules/vpatch-CVE-2023-42793.yaml
crowdsecurity/vpatch-CVE-2023-46805 ✔️ enabled 0.5 /etc/crowdsec/appsec-rules/vpatch-CVE-2023-46805.yaml
crowdsecurity/vpatch-CVE-2023-47218 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2023-47218.yaml
crowdsecurity/vpatch-CVE-2023-49070 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2023-49070.yaml
crowdsecurity/vpatch-CVE-2023-50164 ✔️ enabled 0.7 /etc/crowdsec/appsec-rules/vpatch-CVE-2023-50164.yaml
crowdsecurity/vpatch-CVE-2023-6000 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2023-6000.yaml
crowdsecurity/vpatch-CVE-2023-6553 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2023-6553.yaml
crowdsecurity/vpatch-CVE-2023-7028 ✔️ enabled 0.3 /etc/crowdsec/appsec-rules/vpatch-CVE-2023-7028.yaml
crowdsecurity/vpatch-CVE-2024-0012 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-0012.yaml
crowdsecurity/vpatch-CVE-2024-0204 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-0204.yaml
crowdsecurity/vpatch-CVE-2024-1212 ✔️ enabled 0.4 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-1212.yaml
crowdsecurity/vpatch-CVE-2024-22024 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-22024.yaml
crowdsecurity/vpatch-CVE-2024-23897 ✔️ enabled 0.5 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-23897.yaml
crowdsecurity/vpatch-CVE-2024-27198 ✔️ enabled 0.5 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-27198.yaml
crowdsecurity/vpatch-CVE-2024-27292 ✔️ enabled 0.3 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-27292.yaml
crowdsecurity/vpatch-CVE-2024-27348 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-27348.yaml
crowdsecurity/vpatch-CVE-2024-27564 ✔️ enabled 0.3 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-27564.yaml
crowdsecurity/vpatch-CVE-2024-27954 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-27954.yaml
crowdsecurity/vpatch-CVE-2024-27956 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-27956.yaml
crowdsecurity/vpatch-CVE-2024-28255 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-28255.yaml
crowdsecurity/vpatch-CVE-2024-2862 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-2862.yaml
crowdsecurity/vpatch-CVE-2024-28987 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-28987.yaml
crowdsecurity/vpatch-CVE-2024-29028 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-29028.yaml
crowdsecurity/vpatch-CVE-2024-29824 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-29824.yaml
crowdsecurity/vpatch-CVE-2024-29849 ✔️ enabled 0.5 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-29849.yaml
crowdsecurity/vpatch-CVE-2024-29973 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-29973.yaml
crowdsecurity/vpatch-CVE-2024-32113 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-32113.yaml
crowdsecurity/vpatch-CVE-2024-3272 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-3272.yaml
crowdsecurity/vpatch-CVE-2024-3273 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-3273.yaml
crowdsecurity/vpatch-CVE-2024-32870 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-32870.yaml
crowdsecurity/vpatch-CVE-2024-3408 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-3408.yaml
crowdsecurity/vpatch-CVE-2024-34102 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-34102.yaml
crowdsecurity/vpatch-CVE-2024-38816 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-38816.yaml
crowdsecurity/vpatch-CVE-2024-38856 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-38856.yaml
crowdsecurity/vpatch-CVE-2024-41713 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-41713.yaml
crowdsecurity/vpatch-CVE-2024-4577 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-4577.yaml
crowdsecurity/vpatch-CVE-2024-46506 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-46506.yaml
crowdsecurity/vpatch-CVE-2024-5057 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-5057.yaml
crowdsecurity/vpatch-CVE-2024-51378 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-51378.yaml
crowdsecurity/vpatch-CVE-2024-51482 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-51482.yaml
crowdsecurity/vpatch-CVE-2024-51567 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-51567.yaml
crowdsecurity/vpatch-CVE-2024-51977 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-51977.yaml
crowdsecurity/vpatch-CVE-2024-52301 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-52301.yaml
crowdsecurity/vpatch-CVE-2024-57727 ✔️ enabled 0.4 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-57727.yaml
crowdsecurity/vpatch-CVE-2024-6205 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-6205.yaml
crowdsecurity/vpatch-CVE-2024-6235 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-6235.yaml
crowdsecurity/vpatch-CVE-2024-6671 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-6671.yaml
crowdsecurity/vpatch-CVE-2024-7593 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-7593.yaml
crowdsecurity/vpatch-CVE-2024-8181 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-8181.yaml
crowdsecurity/vpatch-CVE-2024-8190 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-8190.yaml
crowdsecurity/vpatch-CVE-2024-8911 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-8911.yaml
crowdsecurity/vpatch-CVE-2024-8943 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-8943.yaml
crowdsecurity/vpatch-CVE-2024-8963 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-8963.yaml
crowdsecurity/vpatch-CVE-2024-9465 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-9465.yaml
crowdsecurity/vpatch-CVE-2024-9474 ✔️ enabled 0.4 /etc/crowdsec/appsec-rules/vpatch-CVE-2024-9474.yaml
crowdsecurity/vpatch-CVE-2025-10353 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-10353.yaml
crowdsecurity/vpatch-CVE-2025-11700 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-11700.yaml
crowdsecurity/vpatch-CVE-2025-13315 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-13315.yaml
crowdsecurity/vpatch-CVE-2025-13920 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-13920.yaml
crowdsecurity/vpatch-CVE-2025-13956 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-13956.yaml
crowdsecurity/vpatch-CVE-2025-15503 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-15503.yaml
crowdsecurity/vpatch-CVE-2025-24582 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-24582.yaml
crowdsecurity/vpatch-CVE-2025-24786 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-24786.yaml
crowdsecurity/vpatch-CVE-2025-24893 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-24893.yaml
crowdsecurity/vpatch-CVE-2025-25257 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-25257.yaml
crowdsecurity/vpatch-CVE-2025-2611 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-2611.yaml
crowdsecurity/vpatch-CVE-2025-27222 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-27222.yaml
crowdsecurity/vpatch-CVE-2025-27223 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-27223.yaml
crowdsecurity/vpatch-CVE-2025-28367 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-28367.yaml
crowdsecurity/vpatch-CVE-2025-29306 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-29306.yaml
crowdsecurity/vpatch-CVE-2025-29927 ✔️ enabled 0.3 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-29927.yaml
crowdsecurity/vpatch-CVE-2025-31161 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-31161.yaml
crowdsecurity/vpatch-CVE-2025-31324 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-31324.yaml
crowdsecurity/vpatch-CVE-2025-3248 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-3248.yaml
crowdsecurity/vpatch-CVE-2025-34291 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-34291.yaml
crowdsecurity/vpatch-CVE-2025-3605 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-3605.yaml
crowdsecurity/vpatch-CVE-2025-36604 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-36604.yaml
crowdsecurity/vpatch-CVE-2025-37164 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-37164.yaml
crowdsecurity/vpatch-CVE-2025-40552 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-40552.yaml
crowdsecurity/vpatch-CVE-2025-4689 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-4689.yaml
crowdsecurity/vpatch-CVE-2025-47188 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-47188.yaml
crowdsecurity/vpatch-CVE-2025-47812 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-47812.yaml
crowdsecurity/vpatch-CVE-2025-49113 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-49113.yaml
crowdsecurity/vpatch-CVE-2025-49132 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-49132.yaml
crowdsecurity/vpatch-CVE-2025-52488 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-52488.yaml
crowdsecurity/vpatch-CVE-2025-52970 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-52970.yaml
crowdsecurity/vpatch-CVE-2025-53693 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-53693.yaml
crowdsecurity/vpatch-CVE-2025-54249 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-54249.yaml
crowdsecurity/vpatch-CVE-2025-55182 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-55182.yaml
crowdsecurity/vpatch-CVE-2025-55748 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-55748.yaml
crowdsecurity/vpatch-CVE-2025-55749 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-55749.yaml
crowdsecurity/vpatch-CVE-2025-56520 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-56520.yaml
crowdsecurity/vpatch-CVE-2025-57819 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-57819.yaml
crowdsecurity/vpatch-CVE-2025-59528 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-59528.yaml
crowdsecurity/vpatch-CVE-2025-61678 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-61678.yaml
crowdsecurity/vpatch-CVE-2025-61882 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-61882.yaml
crowdsecurity/vpatch-CVE-2025-64446 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-64446.yaml
crowdsecurity/vpatch-CVE-2025-66039 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-66039.yaml
crowdsecurity/vpatch-CVE-2025-8110 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-8110.yaml
crowdsecurity/vpatch-CVE-2025-9316 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2025-9316.yaml
crowdsecurity/vpatch-CVE-2026-0926 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2026-0926.yaml
crowdsecurity/vpatch-CVE-2026-1207 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-CVE-2026-1207.yaml
crowdsecurity/vpatch-CVE-2026-1281 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2026-1281.yaml
crowdsecurity/vpatch-CVE-2026-1557 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2026-1557.yaml
crowdsecurity/vpatch-CVE-2026-20127 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2026-20127.yaml
crowdsecurity/vpatch-CVE-2026-20127-dca-disclosure ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2026-20127-dca-disclosure.yaml
crowdsecurity/vpatch-CVE-2026-21643 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2026-21643.yaml
crowdsecurity/vpatch-CVE-2026-23744 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2026-23744.yaml
crowdsecurity/vpatch-CVE-2026-26980 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2026-26980.yaml
crowdsecurity/vpatch-CVE-2026-27483 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2026-27483.yaml
crowdsecurity/vpatch-CVE-2026-41940 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2026-41940.yaml
crowdsecurity/vpatch-CVE-2026-46725 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2026-46725.yaml
crowdsecurity/vpatch-CVE-2026-61511 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2026-61511.yaml
crowdsecurity/vpatch-CVE-2026-63030 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2026-63030.yaml
crowdsecurity/vpatch-CVE-2026-72898 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2026-72898.yaml
crowdsecurity/vpatch-CVE-2026-9082 ✔️ enabled 0.1 /etc/crowdsec/appsec-rules/vpatch-CVE-2026-9082.yaml
crowdsecurity/vpatch-env-access ✔️ enabled 0.3 /etc/crowdsec/appsec-rules/vpatch-env-access.yaml
crowdsecurity/vpatch-git-config ✔️ enabled 0.5 /etc/crowdsec/appsec-rules/vpatch-git-config.yaml
crowdsecurity/vpatch-laravel-debug-mode ✔️ enabled 0.4 /etc/crowdsec/appsec-rules/vpatch-laravel-debug-mode.yaml
crowdsecurity/vpatch-symfony-profiler ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-symfony-profiler.yaml
crowdsecurity/vpatch-WT-2026-0001 ✔️ enabled 0.2 /etc/crowdsec/appsec-rules/vpatch-WT-2026-0001.yaml

What did you expect to happen?

less exhaustive CPU usage

How can we reproduce it (as minimally and precisely as possible)?

I don't know

Anything else we need to know?

No response

Crowdsec version

Details
$ cscli version 1.8.1
❯ cscli version
version: v1.8.1-909b5157
Codename: alphaga
BuildDate: 2026-09-03_11:03:45
GoVersion: 1.26.8
Platform: docker
libre2: C++
User-Agent: crowdsec/v1.8.1-909b5157-docker
Constraint_parser: >= 1.0, <= 3.0
Constraint_scenario: >= 1.0, <= 3.0
Constraint_api: v1
Constraint_acquis: >= 1.0, < 2.0
Built-in optional components: cscli_setup, datasource_appsec, datasource_cloudwatch, datasource_docker, datasource_file, datasource_http, datasource_journalctl, datasource_k8s-audit, datasource_kafka, datasource_kinesis, datasource_kubernetes, datasource_loki, datasource_s3, datasource_syslog, datasource_victorialogs, datasource_wineventlog, db_mysql, db_postgres, db_sqlite

OS version

Details
# On Linux:
$ cat /etc/os-release
Debian Trixie
$ uname -a
# paste output here

# On Windows:
C:\> wmic os get Caption, Version, BuildNumber, OSArchitecture
# paste output here

Enabled collections and parsers

Details
$ cscli hub list -o raw
# paste output here

Acquisition config

Details
# On Linux:
$ cat /etc/crowdsec/acquis.yaml /etc/crowdsec/acquis.d/*
# paste output here

# On Windows:
C:\> Get-Content C:\ProgramData\CrowdSec\config\acquis.yaml
# paste output here

Config show

Details
$ cscli config show
# paste output here

Prometheus metrics

Details
$ cscli metrics
# paste output here

Related custom configs versions (if applicable) : notification plugins, custom scenarios, parsers etc.

Details

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions