Integer Overflow Vulnerability in compress Library by Klaus Post
CVE-2026-63209
7.5HIGH
What is CVE-2026-63209?
The compress library, developed by Klaus Post, is susceptible to a signed integer overflow vulnerability in its s2.NewDict() function prior to version 1.18.7. Attackers can exploit this flaw by providing a specially crafted dictionary that contains a uvarint-encoded repeat value surpassing MaxInt64. This can result in a negative repeat value when Dict.Encode() is executed, leading to an out-of-bounds memory access through unsafe.Pointer arithmetic. The consequence of this vulnerability is a crash of the process, indicated by a SIGSEGV signal. The issue has been rectified in version 1.18.7.
Affected Version(s)
compress < 1.18.7
