HomeDefault status
unaffected
Any version before 1.24.12
affected
1.25.0 (semver) before 1.25.6
affected
Description
archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service when consuming a maliciously constructed ZIP archive.
Problem types
CWE-407: Inefficient Algorithmic Complexity
Product status
Any version before 1.24.12
1.25.0 (semver) before 1.25.6
Credits
Jakub Ciolek
References
www.openwall.com/lists/oss-security/2026/01/15/4
groups.google.com/g/golang-announce/c/Vd2tYVM8eUc