CVE-2022-4899

HIGH7.5EPSS 0.26%

zstd vulnerable to buffer overrun

Published: 3/31/2023Modified: 2/27/2026
Also known as:GHSA-5c9c-6x87-f9vmPYSEC-2023-121

Description

A vulnerability was found in zstd v1.4.10, where an attacker can supply an empty string as an argument to the command line tool to cause buffer overrun.

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References (12)