CVE-2022-2879None▾ SunlitUnbounded memory consumption when reading headers in archive/tar
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 16.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.5%
1.5% → 1.7%
Reader.Read does not set a limit on the maximum size of file headers. A maliciously crafted archive could cause Read to allocate unbounded amounts of memory, potentially causing resource exhaustion or panics. After fix, Reader.Read limits the maximum size of header blocks to 1 MiB.
stdlib >= 1.19.0-0, < 1.19.2Upgrade to a patched release:
stdlib 1.19.2Connected by shared product, vendor, weakness, or advisory.
CVE-2022-41715NoneMemory exhaustion when compiling regular expressions in regexp/syntax
CVE-2022-2880NoneIncorrect sanitization of forwarded query parameters in net/http/httputil
CVE-2026-56860High· 7.5Avoid quadratic complexity in resolvePath in net/url
CVE-2026-56858High· 8.1Fix Javascript regexp context tracking in html/template
CVE-2026-56862High· 7.5Limit handshake messages we are willing to accept post-handshake in crypto/tls
CVE-2026-56859High· 7.5Add recursion depth guard during decode in encoding/xml