CVE-2025-61728

archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service when consuming a maliciously constructed ZIP archive.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*

History

17 Jun 2026, 09:50

Type Values Removed Values Added
Summary
  • (es) archive/zip usa un algoritmo de indexación de nombres de archivo superlineal que se invoca la primera vez que se abre un archivo en un archivo comprimido. Esto puede provocar una denegación de servicio al consumir un archivo ZIP construido maliciosamente.

06 Feb 2026, 18:45

Type Values Removed Values Added
First Time Golang go
Golang
CPE cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*
CWE CWE-770
References () https://go.dev/cl/736713 - () https://go.dev/cl/736713 - Patch
References () https://go.dev/issue/77102 - () https://go.dev/issue/77102 - Patch
References () https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc - () https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc - Release Notes
References () https://pkg.go.dev/vuln/GO-2026-4342 - () https://pkg.go.dev/vuln/GO-2026-4342 - Vendor Advisory
References () http://www.openwall.com/lists/oss-security/2026/01/15/4 - () http://www.openwall.com/lists/oss-security/2026/01/15/4 - Exploit, Mailing List, Third Party Advisory

29 Jan 2026, 19:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

28 Jan 2026, 21:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/01/15/4 -

28 Jan 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-28 20:16

Updated : 2026-06-17 09:50


NVD link : CVE-2025-61728

Mitre link : CVE-2025-61728

CVE.ORG link : CVE-2025-61728


JSON object : View

Products Affected

golang

  • go
CWE
CWE-770

Allocation of Resources Without Limits or Throttling