CVE-2025-61728

Aliases:GO-2026-4342BIT-golang-2025-61728
Analyzed
Published: 28 Jan 2026, 19:30
Last modified:29 Jan 2026, 18:30

Vulnerability Summary

Overall Risk (default)
medium
36/100
CVSS Score
6.5 MEDIUM
v3.1 (cve.org)
EPSS Score
0.04% LOW
0% probability +0.02%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

28 Jan 2026, 19:30
Published
Vulnerability first disclosed
29 Jan 2026, 18:30
Last Modified
Vulnerability information updated

Description

archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service when consuming a maliciously constructed ZIP archive.

CVSS Metrics

  • v3.1MEDIUMScore: 6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.04% Percentile: 13%

Techniques & Countermeasures

  • CWE-770Allocation of Resources Without Limits or Throttling

    The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Affected Systems

  • go standard libraryarchive/zip

    < 1.24.12 | ≥ 1.25.0, < 1.25.6

  • golanggo

    < 1.24.12 | ≥ 1.25.0, < 1.25.6

  • Gostdlib

    ≥ 1.25.0, < 1.25.6

References (5)