CVE-2025-61728
Location: usr/local/bin/usql_static
Component Name: stdlib
Component Version: v1.25.5
golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip
Target: usr/local/bin/usql_static
Type: gobinary
Fixed version: 1.24.12, 1.25.6
archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service when consuming a maliciously constructed ZIP archive.
关闭于 2026-03-03 0 条评论