Intel

AIKIDO-2025-10720

github.com/vbatts/tar-split is vulnerable to Allocation of Resources Without Limits or Throttling

Allocation of Resources Without Limits or ThrottlingCVE-2025-58183 Published Oct 16, 2025

50

Medium Risk

This Affects:

GOgithub.com/vbatts/tar-split
0.1.0 - 0.12.1
Fixed in 0.12.2
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Unbounded Resource Consumption due to improperly handled untrusted archives. An attacker can exploit this vulnerability by providing a specially crafted archive that, when processed, causes the application to allocate excessive system memory or CPU resources, leading to a denial-of-service condition. This fix is a port of the correction from golang/go@2612dcf(Copyright 2009 The Go Authors).

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/vbatts/tar-split is vulnerable to Allocation of Resources Without Limits or Throttling in versions 0.1.0 - 0.12.1.

How to fix this

Upgrade the github.com/vbatts/tar-split library to the patch version.