CVE-2026-63209 PUBLISHED

Integer Overflow or Wraparound and Out-of-bounds Write in compress

Assigner: GitHub_M
Reserved: 15.07.2026 Published: 29.09.2026 Updated: 29.09.2026

compress provides various compression algorithms. Prior to version 1.18.7, a signed integer overflow vulnerability in s2.NewDict() allows an attacker to bypass repeat index validation by supplying a dictionary with a uvarint-encoded repeat value exceeding MaxInt64. When Dict.Encode() is subsequently called, the overflowed negative repeat value causes an out-of-bounds memory access via unsafe.Pointer arithmetic, crashing the process with SIGSEGV. This issue has been patched in version 1.18.7.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Score: 7.5

Product Status

Vendor klauspost
Product compress
Versions
  • Version < 1.18.7 is affected

References

Problem Types

  • CWE-190: Integer Overflow or Wraparound CWE
  • CWE-787: Out-of-bounds Write CWE