SharpCompress is vulnerable to Denial of Service (DoS)
48
Medium Risk
The tar reader could keep requesting further entries even when the underlying stream could no longer supply a complete header for the next record, which allowed iteration to spin without making forward progress on corrupted or truncated input. The archive facade now treats a failed header read as a terminal archive error instead of continuing the enumeration loop. Regression tests cover advancing the reader after a broken tail so callers get a deterministic failure instead of a hang.
You are affected if you are using a version that falls within the vulnerable range.
SharpCompress is vulnerable to Denial of Service (DoS) in versions 0.10.0 - 0.37.0.
Upgrade the SharpCompress library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant