Vulnerability Report: GO-2025-4020
- CVE-2025-11579, GHSA-rwvp-r38j-9rgg
- Affects: github.com/nwaples/rardecode, github.com/nwaples/rardecode/v2
- Published: Nov 05, 2025
DoS risk due to unrestricted RAR dictionary sizes in github.com/nwaples/rardecode
For detailed information about this vulnerability, visit https://github.com/advisories/GHSA-rwvp-r38j-9rgg.
Affected Packages
-
PathGo VersionsSymbols
-
before v2.2.0
2 unexported affected symbols
- getOptions
- packedFileReader.newArchiveFileFrom
Affected Modules
-
PathGo Versions
-
all versions, no known fixed
Aliases
References
- https://github.com/advisories/GHSA-rwvp-r38j-9rgg
- https://github.com/nwaples/rardecode/commit/52fb4e825c936636f251f7e7deded39ab11df9a9
- https://vuln.go.dev/ID/GO-2025-4020.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.