GO-2026-5046
Dashboard / Vulnerabilities / GO-2026-5046
Summary: CPU exhaustion in Avro decoder in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2
Details: The Avro array and map decoders loop over an attacker-controlled block-count value without checking the underlying reader's error state inside the loop body. Reader.ReadBlockHeader returns the count as a Go int, which is 64-bit on amd64 and arm64 targets. A producer can declare a block of up to math.MaxInt64 elements followed by EOF or any truncated payload, and the decoder will attempt that many no-op iterations before propagating the error. The realistic ceiling is indefinite until the worker is killed externally. A single hostile payload pins a CPU core until the process is OOM-killed, deadline-cancelled, or terminated, resulting in a remote, unauthenticated denial-of-service. The fix exits the loop on the first inner-decode error.
References: https://github.com/iskorotkov/avro/security/advisories/GHSA-w8j3-pq8g-8m7w, https://github.com/iskorotkov/avro/commit/2ce4242e6095d93470ab3b37ed6082b0596f325c, https://github.com/iskorotkov/avro/commit/b124caa58a821f68f100d86f045f9753b88881e8
Affected packages
Package
Name: github.com/iskorotkov/avro/v2
Purl: pkg:golang/github.com/iskorotkov/avro/v2
Affected ranges
Type: SEMVER
Events:
