criticalCVSS 9.8Vulnerability

GHSA-xhj4-g6w8-2xjw

### Impact When deserializing arrays, strings or bytes (blob) types zserio first reads the size of the variable, and then allocates sufficient memory to load data. Since the size is always trusted this can be abused by creating a data file with a large size value, causing the zserio runtime to allocate large amounts of memory. ### Patches Please apply [this commit](https://github.com/woven-by-toyota/go-zserio/commit/39ef1decde7e9766207794d396018776b33c6e45). ### Workarounds - Do not accept zserio data from non-trusted sources. - Use secure transportation protocols (like TLS).

Properties

ghsa_id
GHSA-xhj4-g6w8-2xjw
severity
critical
summary
go-zserio has Unbounded Memory Allocation for All Platforms
cvss_score
9.8
cve_id
GHSA-xhj4-g6w8-2xjw
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
is_ghsa_only
true
ghsa_published
2026-04-24T16:25:54Z
source_url
https://github.com/advisories/GHSA-xhj4-g6w8-2xjw
ghsa_updated
2026-04-24T16:25:55Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]go/github.com/woven-planet/go-zserio

AFFECTS (1)

[Software]go/github.com/woven-planet/go-zserio

HAS_WEAKNESS (1)

[Weakness]Memory Allocation with Excessive Size Value

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph