Improper Handling of Highly Compressed Data (Data Amplification) Affecting github.com/ackites/killwxapkg/internal/unpack package, versions >=0.0.0


Severity

Recommended
0.0
low
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.04% (11th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMACKITESKILLWXAPKGINTERNALUNPACK-10245512
  • published28 May 2025
  • disclosed21 May 2025
  • creditac0d3r

Introduced: 21 May 2025

NewCVE-2025-5031  (opens in a new tab)
CWE-409  (opens in a new tab)

How to fix?

There is no fixed version for github.com/Ackites/KillWxapkg/internal/unpack.

Overview

Affected versions of this package are vulnerable to Improper Handling of Highly Compressed Data (Data Amplification) via a specially crafted wxapkg file. An attacker can cause resource consumption by sending specially crafted zip files that exploit the decompression process and convincing a user to decompress them.

CVSS Base Scores

version 4.0
version 3.1