CVE-2025-61728 — Allocation of Resources Without Limits or Throttling in Standard Library Archive ZIP
Severity
6.5MEDIUMNVD
GHSA7.5OSV7.5
EPSS
0.0%
top 95.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 28
Latest updateFeb 19
Description
archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service when consuming a maliciously constructed ZIP archive.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6
Affected Packages3 packages
Patches
🔴Vulnerability Details
6GHSA▶
GHSA-g9q4-qjx4-2v7q: archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened↗2026-01-28
📋Vendor Advisories
2🕵️Threat Intelligence
2💬Community
1Bugzilla▶
CVE-2025-61728 golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip↗2026-01-28