CVE-2025-61728: Golang Go
Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.
archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service when consuming a maliciously constructed ZIP archive.
Affected products
- Golang Go: before 1.24.12 (fixed in 1.24.12); from 1.25.0, before 1.25.6 (fixed in 1.25.6)
Published 2026-01-28. Last modified 2026-06-17.