GHSA-25xm-hr59-7c27

    Dashboard / Vulnerabilities / GHSA-25xm-hr59-7c27

    GHSA-25xm-hr59-7c27

    Published: 25 May 2021Last Modified: 8 Jul 2026

    Summary: github.com/ulikunitz/xz fixes readUvarint Denial of Service (DoS)

    Details: ### Impact xz is a compression and decompression library focusing on the xz format completely written in Go. The function readUvarint used to read the xz container format may not terminate a loop provide malicous input. ### Patches The problem has been fixed in release v0.5.8. ### Workarounds Limit the size of the compressed file input to a reasonable size for your use case. ### References The standard library had recently the same issue and got the [CVE-2020-16845](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-16845) allocated. ### For more information If you have any questions or comments about this advisory: * Open an issue in [xz](https://github.com/ulikunitz/xz/issues).

    Affected packages

    Package

    Name: github.com/ulikunitz/xz

    Purl: pkg:golang/github.com/ulikunitz/xz

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -0.5.8

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-25xm-hr59-7c27 | CVE-DB