Vulnerability Report: GO-2026-4342
- CVE-2025-61728, CVE-2025-61728
- Affects: archive/zip
- Published: Jan 28, 2026
archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service when consuming a maliciously constructed ZIP archive.
Affected Packages
-
PathVersionsSymbols
-
before go1.24.12, from go1.25.0 before go1.25.6
Aliases
References
- https://go.dev/cl/736713
- https://go.dev/issue/77102
- https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc
- https://vuln.go.dev/ID/GO-2026-4342.json
Credits
- Jakub Ciolek
Feedback
See anything missing or incorrect?
Suggest an edit to this report.