ThreatCluster

Multiple CVEs Affecting ZIP Archive Handling in Go

First seen 18 Feb 2026, 10:13 UTC Api.Msrc.Microsoft 41

Article Content

Browse articles
ThreatCluster

Two vulnerabilities related to ZIP archive handling in Go have been reported. CVE-2021-41772, published on November 8, 2021, allows a panic via a crafted ZIP archive with an invalid name or empty filename field. CVE-2024-0450, published on March 19, 2024, involves issues with quoted ZIP files.

Timeline

2021-11-08
CVE-2021-41772 published
2024-03-19
CVE-2024-0450 published
2026-02-18
Both CVEs reported in articles