Integer Overflow Vulnerability in compress Library by Klaus Post
CVE-2026-63209

7.5HIGH

Key Information:

Vendor

Klauspost

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-63209?

The compress library, developed by Klaus Post, is susceptible to a signed integer overflow vulnerability in its s2.NewDict() function prior to version 1.18.7. Attackers can exploit this flaw by providing a specially crafted dictionary that contains a uvarint-encoded repeat value surpassing MaxInt64. This can result in a negative repeat value when Dict.Encode() is executed, leading to an out-of-bounds memory access through unsafe.Pointer arithmetic. The consequence of this vulnerability is a crash of the process, indicated by a SIGSEGV signal. The issue has been rectified in version 1.18.7.

Affected Version(s)

compress < 1.18.7

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.