github.com/ulikunitz/xz
Activity
- Latest release
- 1mo ago
- Total releases
- 20
- Cadence
- ~4 months
- Last 12 months
- 2
Reach
- Stars
- —
Details
- First release
- Feb 15, 2017
| Version | Released | |
|---|---|---|
v0.5.16
patch
|
v0.5.16
patch
|
|
v0.6.0-last-dev
pre
|
v0.6.0-last-dev
pre
Dependencies (1)
|
|
v0.5.15
patch
|
v0.5.15
patch
|
|
v0.5.14
patch
1 CVE
CVE-2025-58058
GO-2025-3922
GHSA-jc7w-c686-c4v9
Sep 17, 2025
Memory leaks when decoding a corrupted multiple LZMA archives in github.com/ulikunitz/xz Memory leaks when decoding a corrupted multiple LZMA archives in github.com/ulikunitz/xz Fixed in
0.5.15
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.5.14
patch
|
|
v0.5.14-rc.1
pre
1 CVE
CVE-2025-58058
GO-2025-3922
GHSA-jc7w-c686-c4v9
Sep 17, 2025
Memory leaks when decoding a corrupted multiple LZMA archives in github.com/ulikunitz/xz Memory leaks when decoding a corrupted multiple LZMA archives in github.com/ulikunitz/xz Fixed in
0.5.15
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.5.14-rc.1
pre
|
|
v0.5.13
patch
1 CVE
CVE-2025-58058
GO-2025-3922
GHSA-jc7w-c686-c4v9
Sep 17, 2025
Memory leaks when decoding a corrupted multiple LZMA archives in github.com/ulikunitz/xz Memory leaks when decoding a corrupted multiple LZMA archives in github.com/ulikunitz/xz Fixed in
0.5.15
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.5.13
patch
|
|
v0.5.12
patch
1 CVE
CVE-2025-58058
GO-2025-3922
GHSA-jc7w-c686-c4v9
Sep 17, 2025
Memory leaks when decoding a corrupted multiple LZMA archives in github.com/ulikunitz/xz Memory leaks when decoding a corrupted multiple LZMA archives in github.com/ulikunitz/xz Fixed in
0.5.15
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.5.12
patch
|
|
v0.6.0-alpha.3
pre
|
v0.6.0-alpha.3
pre
Dependencies (1)
|
|
v0.6.0-alpha.2
pre
|
v0.6.0-alpha.2
pre
Dependencies (1)
|
|
v0.6.0-alpha1
pre
|
v0.6.0-alpha1
pre
Dependencies (1)
|
|
v0.6.0-alpha.1
pre
|
v0.6.0-alpha.1
pre
Dependencies (1)
|
|
v0.5.11
patch
1 CVE
CVE-2025-58058
GO-2025-3922
GHSA-jc7w-c686-c4v9
Sep 17, 2025
Memory leaks when decoding a corrupted multiple LZMA archives in github.com/ulikunitz/xz Memory leaks when decoding a corrupted multiple LZMA archives in github.com/ulikunitz/xz Fixed in
0.5.15
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.5.11
patch
|
|
v0.5.10
patch
1 CVE
CVE-2025-58058
GO-2025-3922
GHSA-jc7w-c686-c4v9
Sep 17, 2025
Memory leaks when decoding a corrupted multiple LZMA archives in github.com/ulikunitz/xz Memory leaks when decoding a corrupted multiple LZMA archives in github.com/ulikunitz/xz Fixed in
0.5.15
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.5.10
patch
|
|
v0.5.9
patch
1 CVE
CVE-2025-58058
GO-2025-3922
GHSA-jc7w-c686-c4v9
Sep 17, 2025
Memory leaks when decoding a corrupted multiple LZMA archives in github.com/ulikunitz/xz Memory leaks when decoding a corrupted multiple LZMA archives in github.com/ulikunitz/xz Fixed in
0.5.15
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.5.9
patch
|
|
v0.5.8
patch
1 CVE
CVE-2025-58058
GO-2025-3922
GHSA-jc7w-c686-c4v9
Sep 17, 2025
Memory leaks when decoding a corrupted multiple LZMA archives in github.com/ulikunitz/xz Memory leaks when decoding a corrupted multiple LZMA archives in github.com/ulikunitz/xz Fixed in
0.5.15
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.5.8
patch
|
|
v0.5.7
patch
2 CVEs
CVE-2025-58058
GO-2025-3922
GHSA-jc7w-c686-c4v9
Sep 17, 2025
Memory leaks when decoding a corrupted multiple LZMA archives in github.com/ulikunitz/xz Memory leaks when decoding a corrupted multiple LZMA archives in github.com/ulikunitz/xz Fixed in
0.5.15
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-29482
GHSA-25xm-hr59-7c27
GO-2020-0016
May 25, 2021
github.com/ulikunitz/xz fixes readUvarint Denial of Service (DoS)
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Impactxz is a compression and decompression library focusing on the xz format completely written in Go. The function readUvarint used to read the xz container format may not terminate a loop provide malicous input. PatchesThe problem has been fixed in release v0.5.8. WorkaroundsLimit the size of the compressed file input to a reasonable size for your use case. ReferencesThe standard library had recently the same issue and got the CVE-2020-16845 allocated. For more informationIf you have any questions or comments about this advisory:
Fixed in
0.5.8
References Updated Jul 08, 2026 · Source: OSV.dev |
v0.5.7
patch
|
|
v0.5.6
patch
2 CVEs
CVE-2025-58058
GO-2025-3922
GHSA-jc7w-c686-c4v9
Sep 17, 2025
Memory leaks when decoding a corrupted multiple LZMA archives in github.com/ulikunitz/xz Memory leaks when decoding a corrupted multiple LZMA archives in github.com/ulikunitz/xz Fixed in
0.5.15
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-29482
GHSA-25xm-hr59-7c27
GO-2020-0016
May 25, 2021
github.com/ulikunitz/xz fixes readUvarint Denial of Service (DoS)
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Impactxz is a compression and decompression library focusing on the xz format completely written in Go. The function readUvarint used to read the xz container format may not terminate a loop provide malicous input. PatchesThe problem has been fixed in release v0.5.8. WorkaroundsLimit the size of the compressed file input to a reasonable size for your use case. ReferencesThe standard library had recently the same issue and got the CVE-2020-16845 allocated. For more informationIf you have any questions or comments about this advisory:
Fixed in
0.5.8
References Updated Jul 08, 2026 · Source: OSV.dev |
v0.5.6
patch
|
|
v0.5.5
patch
2 CVEs
CVE-2025-58058
GO-2025-3922
GHSA-jc7w-c686-c4v9
Sep 17, 2025
Memory leaks when decoding a corrupted multiple LZMA archives in github.com/ulikunitz/xz Memory leaks when decoding a corrupted multiple LZMA archives in github.com/ulikunitz/xz Fixed in
0.5.15
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-29482
GHSA-25xm-hr59-7c27
GO-2020-0016
May 25, 2021
github.com/ulikunitz/xz fixes readUvarint Denial of Service (DoS)
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Impactxz is a compression and decompression library focusing on the xz format completely written in Go. The function readUvarint used to read the xz container format may not terminate a loop provide malicous input. PatchesThe problem has been fixed in release v0.5.8. WorkaroundsLimit the size of the compressed file input to a reasonable size for your use case. ReferencesThe standard library had recently the same issue and got the CVE-2020-16845 allocated. For more informationIf you have any questions or comments about this advisory:
Fixed in
0.5.8
References Updated Jul 08, 2026 · Source: OSV.dev |
v0.5.5
patch
|
|
v0.5.4
patch
2 CVEs
CVE-2025-58058
GO-2025-3922
GHSA-jc7w-c686-c4v9
Sep 17, 2025
Memory leaks when decoding a corrupted multiple LZMA archives in github.com/ulikunitz/xz Memory leaks when decoding a corrupted multiple LZMA archives in github.com/ulikunitz/xz Fixed in
0.5.15
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-29482
GHSA-25xm-hr59-7c27
GO-2020-0016
May 25, 2021
github.com/ulikunitz/xz fixes readUvarint Denial of Service (DoS)
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Impactxz is a compression and decompression library focusing on the xz format completely written in Go. The function readUvarint used to read the xz container format may not terminate a loop provide malicous input. PatchesThe problem has been fixed in release v0.5.8. WorkaroundsLimit the size of the compressed file input to a reasonable size for your use case. ReferencesThe standard library had recently the same issue and got the CVE-2020-16845 allocated. For more informationIf you have any questions or comments about this advisory:
Fixed in
0.5.8
References Updated Jul 08, 2026 · Source: OSV.dev |
v0.5.4
patch
|
|
v0.5.3
initial
2 CVEs
CVE-2025-58058
GO-2025-3922
GHSA-jc7w-c686-c4v9
Sep 17, 2025
Memory leaks when decoding a corrupted multiple LZMA archives in github.com/ulikunitz/xz Memory leaks when decoding a corrupted multiple LZMA archives in github.com/ulikunitz/xz Fixed in
0.5.15
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-29482
GHSA-25xm-hr59-7c27
GO-2020-0016
May 25, 2021
github.com/ulikunitz/xz fixes readUvarint Denial of Service (DoS)
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Impactxz is a compression and decompression library focusing on the xz format completely written in Go. The function readUvarint used to read the xz container format may not terminate a loop provide malicous input. PatchesThe problem has been fixed in release v0.5.8. WorkaroundsLimit the size of the compressed file input to a reasonable size for your use case. ReferencesThe standard library had recently the same issue and got the CVE-2020-16845 allocated. For more informationIf you have any questions or comments about this advisory:
Fixed in
0.5.8
References Updated Jul 08, 2026 · Source: OSV.dev |
v0.5.3
initial
|