Uncaught Exception Affecting std/archive/zip package, versions <1.16.10>=1.17.0-0 <1.17.3


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
3.05% (86th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-STDARCHIVEZIP-14564418
  • published6 Jan 2026
  • disclosed13 Jan 2022
  • creditColin Arnott, Noah Santschi-Cooney

Introduced: 13 Jan 2022

CVE-2021-41772  (opens in a new tab)
CWE-248  (opens in a new tab)

How to fix?

Upgrade std/archive/zip to version 1.16.10, 1.17.3 or higher.

Overview

std/archive/zip is a Go standard library package std/archive/zip

Affected versions of this package are vulnerable to Uncaught Exception.

Go Vulnerability Report:
via the Open function in the archive/zip package when processing zip files containing entries with names composed solely of slash characters or ".." path elements, or when an empty string is provided as an argument. An attacker can cause a panic and potentially disrupt application availability by crafting a malicious zip file with such entries.

CVSS Base Scores

version 4.0
version 3.1