GHSA-xhj4-g6w8-2xjw

Suggest an improvement
Source
https://github.com/advisories/GHSA-xhj4-g6w8-2xjw
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-xhj4-g6w8-2xjw/GHSA-xhj4-g6w8-2xjw.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-xhj4-g6w8-2xjw
Aliases
Published
2026-04-24T16:25:54Z
Modified
2026-06-25T23:11:47Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
go-zserio has Unbounded Memory Allocation for All Platforms
Details

Impact

When deserializing arrays, strings or bytes (blob) types zserio first reads the size of the variable, and then allocates sufficient memory to load data. Since the size is always trusted this can be abused by creating a data file with a large size value, causing the zserio runtime to allocate large amounts of memory.

Patches

Please apply this commit.

Workarounds

  • Do not accept zserio data from non-trusted sources.
  • Use secure transportation protocols (like TLS).
Database specific
{
    "cwe_ids":  [
        "CWE-789"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-04-24T16:25:54Z",
    "nvd_published_at":  null,
    "severity":  "CRITICAL"
}
References

Affected packages

Go / github.com/woven-planet/go-zserio

Package

Name
github.com/woven-planet/go-zserio
View open source insights on deps.dev
Purl
pkg:golang/github.com/woven-planet/go-zserio

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.9.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-xhj4-g6w8-2xjw/GHSA-xhj4-g6w8-2xjw.json"