GHSA-jpxj-2jvg-6jv9
GitHub Security Advisory
Data Amplification in HashiCorp go-getter
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
HashiCorp go-getter up to 1.6.2 and 2.1.1 is vulnerable to decompression bombs. Fixed in 1.7.0 and 2.2.0.
Affected Packages
Go
github.com/hashicorp/go-getter
Affected versions:
0
(fixed in 1.7.0)
Go
github.com/hashicorp/go-getter/v2
Affected versions:
2.0.0
(fixed in 2.2.0)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 7, 2025 6:28 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.