Intel

AIKIDO-2025-10950

github.com/gabriel-vasile/mimetype is vulnerable to Integer Overflow

Integer Overflow Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Dec 15, 2025

48

Medium Risk

This Affects:

GOgithub.com/gabriel-vasile/mimetype
1.4.10 - 1.4.11
Fixed in 1.4.12
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to an integer overflow in offset calculation, where the package searches for a value within input using an offset also derived from input, allowing integer overflow. An attacker can exploit this by supplying malicious input that triggers an overflow, leading to out-of-bounds memory access, which may result in denial of service, information disclosure, or arbitrary code execution.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and if you're using a 32-BIT architecture.

Background info

github.com/gabriel-vasile/mimetype is vulnerable to Integer Overflow in versions 1.4.10 - 1.4.11.

How to fix this

Upgrade the github.com/gabriel-vasile/mimetype library to the patch version.