Description

archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service when consuming a maliciously constructed ZIP archive.

INFO

Published Date :

2026-01-28T19:30:31.354Z

Last Modified :

2026-01-29T18:30:24.487Z

Source :

Go
AFFECTED PRODUCTS

The following products are affected by CVE-2025-61728 vulnerability.

Vendors Products
Go Standard Library
  • Archive/zip
Golang
  • Go

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact