CVE-2025-61728Allocation of Resources Without Limits or Throttling in Standard Library Archive ZIP

Severity
6.5MEDIUMNVD
GHSA7.5OSV7.5
EPSS
0.0%
top 95.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 28
Latest updateFeb 19

Description

archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service when consuming a maliciously constructed ZIP archive.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

CVEListV5go_standard_library/archive_zip1.25.01.25.6+1
NVDgolang/go1.25.01.25.6+1

Patches

🔴Vulnerability Details

6
GHSA
Centrifugo v6.6.0 dependency vulnerabilities2026-02-19
OSV
Centrifugo v6.6.0 dependency vulnerabilities2026-02-19
GHSA
GHSA-g9q4-qjx4-2v7q: archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened2026-01-28
OSV
Excessive CPU consumption when building archive index in archive/zip2026-01-28
CVEList
Excessive CPU consumption when building archive index in archive/zip2026-01-28

📋Vendor Advisories

2
Red Hat
golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip2026-01-28
Debian
CVE-2025-61728: golang-1.15 - archive/zip uses a super-linear file name indexing algorithm that is invoked the...2025

🕵️Threat Intelligence

2
Wiz
CVE-2025-61728 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
GHSA-j9wf-6r2x-hqmx Impact, Exploitability, and Mitigation Steps | Wiz

💬Community

1
Bugzilla
CVE-2025-61728 golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip2026-01-28
CVE-2025-61728 — MEDIUM severity | cvebase