Loading HuntDB...

GHSA-fqpx-62jv-7r6r

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

Reader.Read does not set a limit on the maximum size of file headers. A maliciously crafted archive could cause Read to allocate unbounded amounts of memory, potentially causing resource exhaustion or panics. After fix, Reader.Read limits the maximum size of header blocks to 1 MiB.

Related CVEs

Key Information

GHSA ID
GHSA-fqpx-62jv-7r6r
Published
October 14, 2022 7:00 PM
Last Modified
October 18, 2022 7:00 PM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 17, 2025 2:40 PM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.