Buffer Over-read Affecting gzip package, versions [0,]


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.34% (26th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-GZIP-17705241
  • published30 Jun 2026
  • disclosed29 Jun 2026
  • creditUnknown

Introduced: 29 Jun 2026

CVE-2026-41992  (opens in a new tab)
CWE-126  (opens in a new tab)

How to fix?

A fix was pushed into the master branch but not yet published.

Overview

Affected versions of this package are vulnerable to Buffer Over-read in the LZH decompression process due to improper reuse of shared global state between different decompression formats within a single execution. An attacker can cause an out-of-bounds read by decompressing a specially crafted LZW file followed by a specially crafted LZH file in a single execution, leading to reading past the end of the allocated global buffer. This is only exploitable if both file types are processed in the same invocation.

References

CVSS Base Scores

version 4.0
version 3.1