GHSA-pqqp-7cp8-vxvf

Suggest an improvement
Source
https://github.com/advisories/GHSA-pqqp-7cp8-vxvf
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/05/GHSA-pqqp-7cp8-vxvf/GHSA-pqqp-7cp8-vxvf.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-pqqp-7cp8-vxvf
Aliases
Published
2025-05-21T18:33:31Z
Modified
2025-05-23T16:13:17.568295Z
Severity
  • 3.1 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L CVSS Calculator
  • 2.3 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
Ackites KillWxapkg Zip Bomb Resource Exhaustion
Details

A vulnerability was found in Ackites KillWxapkg up to 2.4.1. It has been rated as problematic. This issue affects some unknown processing of the component wxapkg File Decompression Handler. The manipulation leads to resource consumption. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.

Database specific
{
    "nvd_published_at": "2025-05-21T17:15:59Z",
    "cwe_ids": [
        "CWE-400"
    ],
    "severity": "LOW",
    "github_reviewed": true,
    "github_reviewed_at": "2025-05-21T20:11:03Z"
}
References

Affected packages

Go / github.com/Ackites/KillWxapkg

Package

Name
github.com/Ackites/KillWxapkg
View open source insights on deps.dev
Purl
pkg:golang/github.com/Ackites/KillWxapkg

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
1.1.0