SharpCompress is vulnerable to Denial of Service (DoS)
43
Medium Risk
Reading certain RAR archives with comment metadata could throw during header handling instead of completing or failing in a controlled way. Some tar streams produced with oldgnu layouts can carry uid and gid values that overflow assumptions in header parsing and break reads for otherwise valid archives. LZMA-framed streams could miss end-of-stream handling in edge cases, leaving decompression in an inconsistent state when the payload does not match expectations. The release tightens those parse paths and adds regression coverage; failures remain catchable managed exceptions unless the host process opts not to handle them.
You are affected if you are using a version that falls within the vulnerable range.
SharpCompress is vulnerable to Denial of Service (DoS) in versions 0.10.0 - 0.34.2.
Upgrade the SharpCompress library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant