SharpCompress is vulnerable to Denial of Service (DoS)
48
Medium Risk
The tar reader could keep requesting further entries even when the underlying stream could no longer supply a complete header for the next record, which allowed iteration to spin without making forward progress on corrupted or truncated input. The archive facade now treats a failed header read as a terminal archive error instead of continuing the enumeration loop. Regression tests cover advancing the reader after a broken tail so callers get a deterministic failure instead of a hang.
You are affected if you are using a version that falls within the vulnerable range.
SharpCompress is vulnerable to Denial of Service (DoS) in versions 0.10.0 - 0.37.0.
Upgrade the SharpCompress library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant