CVE-2024-34156: Go Standard Library Encoding/gob

High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.

Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. This is a follow-up to CVE-2022-30635.

Affected products

  • Go Standard Library Encoding/gob: before 1.22.7 (fixed in 1.22.7); from 1.23.0-0, before 1.23.1 (fixed in 1.23.1)
  • Go Standard Library Encoding\/gob: before 1.22.7 (fixed in 1.22.7); from 1.23.0-0, before 1.23.1 (fixed in 1.23.1)

Published 2024-09-06. Last modified 2026-06-17.