GO-2026-5047
Dashboard / Vulnerabilities / GO-2026-5047
Summary: Integer overflow in Avro decoder in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2
Details: Several Avro decoder paths read attacker-controlled 64-bit values from the wire format and either narrowed them to platform-sized int before bounds-checking, or summed them with overflow-prone signed-int arithmetic. On 32-bit targets, the truncation paths can silently bypass byte-slice limits, select the wrong union branch, or hit a negative-make panic via wrap. Three sub-issues are not 32-bit-specific: cumulative-size arithmetic overflow in array and map decoders, negation of MinInt in block-header handling, and negative size in block reads. All three panic or bypass caps on any platform, giving an attacker a denial-of-service primitive. Exploitation requires only an untrusted Avro stream.
References: https://github.com/iskorotkov/avro/security/advisories/GHSA-mc57-h6j3-3hmv, https://github.com/iskorotkov/avro/commit/bed99b315ec097a1a5eb7ae074ef57a91848c583, https://github.com/iskorotkov/avro/commit/e1a570f9a8a4fe4b1bc2b4b1fb6d24e4a5f04358
Affected packages
Package
Name: github.com/iskorotkov/avro/v2
Purl: pkg:golang/github.com/iskorotkov/avro/v2
Affected ranges
Type: SEMVER
Events:
