algorand / algorand/go-algorand

Vulnerability in go-algorand project

Aperta
#6,606 1 commento 0 reazioni 0 assegnatari Vedi su GitHub
bug
Lingua principale
Go
Stelle
1.4k
Fork
537
Merge medio
1g 7h
PR unite (30g)
18

Descrizione

While working on go-algorand project, I scanned the dependency manifest and found that it uses a vulnerable version of **`github.com/ipld/go-ipld-prime`**. The scan revealed an unbounded memory allocation issue in the DAG-CBOR decoder, where crafted payloads can trigger excessive memory usage, potentially leading to a denial of service.

[CVE Report](https://vulert.com/vuln-scan/list/baa78ea9-b0e6-4add-bc77-392a6d331e5c?sort_order=desc&sort_by=created_at)
[CVE Link](https://vulert.com/vuln-db/CVE-2026-35480)

Guida per i contributori

Apri la guida per i contributori

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.