{"id":"CVE-2021-29482","aliases":["GHSA-25xm-hr59-7c27","GO-2020-0016"],"url":"https://o3.security/vulnerability/CVE-2021-29482","summary":"github.com/ulikunitz/xz fixes readUvarint Denial of Service (DoS)","details":"xz is a compression and decompression library focusing on the xz format completely written in Go. The function readUvarint used to read the xz container format may not terminate a loop provide malicous input. The problem has been fixed in release v0.5.8. As a workaround users can limit the size of the compressed file input to a reasonable size for their use case. The standard library had recently the same issue and got the CVE-2020-16845 allocated.","published":"2021-04-28T19:15:08.587Z","modified":"2026-07-09T10:52:41.068708Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":{"score":0.01438,"percentile":0.71645,"asOf":"2026-09-13"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/ulikunitz/xz","fixedVersion":"0.5.8"}],"fix":{"url":"https://github.com/ulikunitz/xz/commit/69c6093c7b2397b923acf82cb378f55ab2652b9b","label":"ulikunitz/xz@69c6093"},"references":[{"type":"ADVISORY","url":"https://github.com/ulikunitz/xz/security/advisories/GHSA-25xm-hr59-7c27"},{"type":"FIX","url":"https://github.com/ulikunitz/xz/commit/69c6093c7b2397b923acf82cb378f55ab2652b9b"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T10:52:41.068708Z"}}