xz vulnerabilities
CVEs whose affected-version data names the xz package (xz-utils). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-34743Medium· 5.3XZ Utils provide a general-purpose data-compression library plus command-line tools
XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state wher…
▾ Sunlittukaani · xzEPSS 0.45%via NVD
CVE-2024-3094Critical· 10.0PoCMalicious backdoor in xz/liblzma (supply-chain compromise)
A backdoor was intentionally introduced into the xz-utils upstream release tarballs (5.6.0 / 5.6.1). When linked into sshd via liblzma, it allows a remote attacker holding a specific key to bypass authentication and execute commands.
▾ Abyssalliblzma · liblzmaLinuxEPSS 86%via GHSA