PT-2026-25101 · Go · Github.Com/Chainguard-Dev/Malcontent

Published

2026-03-02

·

Updated

2026-03-02

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Several extraction and scanning code paths registered late defers which could leak resources and exhaust system resources.
This report is an aggregate of these individual reports for the affected code:
AdvisoryAffected File
GHSA-jjgh-mc5q-gch7pkg/action/scan.go
GHSA-mwmf-fxh2-w4x7pkg/archive/deb.go
GHSA-p8j3-rpf5-gwv3pkg/archive/gzip.go
GHSA-qfh4-7f5v-75gqpkg/archive/zlib.go
GHSA-wxxf-r586-5rf5pkg/archive/bzip2.go
Fix: #1354, #1355, #1356, #1361
Acknowledgements
Thank you to Oleh Konko from 1seal for discovering and reporting all six of these issues.

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-54P8-X2M9-C593

Affected Products

Github.Com/Chainguard-Dev/Malcontent