Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-61728

Опубликовано: 28 янв. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service when consuming a maliciously constructed ZIP archive.

A flaw was found in the archive/zip package in the Go standard library. A super-linear file name indexing algorithm is used in the first time a file in an archive is opened. A crafted zip archive containing a specific arrangement of file names can cause an excessive CPU and memory consumption. A Go application processing a malicious archive can become unresponsive or crash, resulting in a denial of service.

Отчет

To exploit this flaw, an attacker needs to be able to process a malicious zip archive with an application using the archive/zip package. Additionally, this vulnerability can cause a Go application to consume an excessive amount of CPU and memory, eventually resulting in a denial of service with no other security impact. Due to these reasons, this flaw has been rated with a moderate severity.

Меры по смягчению последствий

To mitigate this vulnerability, implement a timeout in your archive/zip processing logic to abort the operation if it exceeds a few seconds, preventing the application from consuming an excessive amount of resources.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Confidential Compute Attestationopenshift-sandboxed-containers/osc-cloud-api-adaptor-rhel9Affected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-payload-rhel9Affected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-rhel9-operatorAffected
Deployment Validation Operatordvo/deployment-validation-rhel8-operatorAffected
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/external-secrets-rhel9Not affected
Migration Toolkit for Applications 8mta/mta-cli-rhel9Affected
Migration Toolkit for Applications 8mta/mta-dotnet-external-provider-rhel8Affected
Migration Toolkit for Applications 8mta/mta-dotnet-external-provider-rhel9Affected
Migration Toolkit for Applications 8mta/mta-generic-external-provider-rhel9Affected
Migration Toolkit for Applications 8mta/mta-java-external-provider-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2434431golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip

EPSS

Процентиль: 46%
0.00643
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
5 месяцев назад

archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service when consuming a maliciously constructed ZIP archive.

CVSS3: 6.5
nvd
5 месяцев назад

archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service when consuming a maliciously constructed ZIP archive.

CVSS3: 6.5
debian
5 месяцев назад

archive/zip uses a super-linear file name indexing algorithm that is i ...

CVSS3: 6.5
github
5 месяцев назад

archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service when consuming a maliciously constructed ZIP archive.

CVSS3: 6.5
fstec
5 месяцев назад

Уязвимость языка программирования Golang, связанная с неограниченным распределением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 46%
0.00643
Низкий

7.5 High

CVSS3

Уязвимость CVE-2025-61728