Related Vulnerabilities: CVE-2021-33196  

A security issue has been found in Go. Due to a pre-allocation optimization in zip.NewReader, a malformed archive which indicates it has a significant number of files can cause either a panic or memory exhaustion.

Severity Low

Remote Yes

Type Denial of service

Description

A security issue has been found in Go. Due to a pre-allocation optimization in zip.NewReader, a malformed archive which indicates it has a significant number of files can cause either a panic or memory exhaustion.

AVG-2006 go 2:1.16.4-1 Low Vulnerable

https://github.com/golang/go/issues/46242
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=33912
https://go.googlesource.com/go/+/ea6b0bf4faa91ad43e255a8d480a9e2b0f70dfc1%5E%21/