algorand / algorand/go-algorand
Vulnerability in go-algorand project
Aperta
bug
- Lingua principale
- Go
- Stelle
- 1.4k
- Fork
- 537
- Merge medio
- 1g 7h
- PR unite (30g)
- 18
Descrizione
While working on go-algorand project, I scanned the dependency manifest and found that it uses a vulnerable version of **`github.com/ipld/go-ipld-prime`**. The scan revealed an unbounded memory allocation issue in the DAG-CBOR decoder, where crafted payloads can trigger excessive memory usage, potentially leading to a denial of service.
[CVE Report](https://vulert.com/vuln-scan/list/baa78ea9-b0e6-4add-bc77-392a6d331e5c?sort_order=desc&sort_by=created_at)
[CVE Link](https://vulert.com/vuln-db/CVE-2026-35480)
Guida per i contributori
Apri la guida per i contributori
Valutazione
Questa issue non è ancora stata valutata.