Stack Exhaustion Vulnerabilities in Go Libraries Identified
First seen 18 Feb 2026, 13:23 UTC
•
•39
Export
Article Content
Browse articles
Two stack exhaustion vulnerabilities have been reported in Go libraries. CVE-2024-34156 affects the Decoder.Decode function in the encoding/gob package, while CVE-2022-30631 impacts the compress/gzip package when reading certain archives. Both vulnerabilities have been documented by Microsoft as of February 18, 2026.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Timeline
2022-08-09
CVE-2022-30631 published
2024-09-06
CVE-2024-34156 published
2026-02-18
Information published about both vulnerabilities