SharpCompress is vulnerable to Denial of Service (DoS)
43
Medium Risk
Reading certain RAR archives with comment metadata could throw during header handling instead of completing or failing in a controlled way. Some tar streams produced with oldgnu layouts can carry uid and gid values that overflow assumptions in header parsing and break reads for otherwise valid archives. LZMA-framed streams could miss end-of-stream handling in edge cases, leaving decompression in an inconsistent state when the payload does not match expectations. The release tightens those parse paths and adds regression coverage; failures remain catchable managed exceptions unless the host process opts not to handle them.
You are affected if you are using a version that falls within the vulnerable range.
SharpCompress is vulnerable to Denial of Service (DoS) in versions 0.10.0 - 0.34.2.
Upgrade the SharpCompress library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant