CVE-2022-36078 is a memory allocation vulnerability affecting the github.com/gagliardetto/binary library. It allows an attacker to trigger excessive memory allocation or program crashes by providing crafted input that causes slices to be allocated with arbitrary, large sizes. This vulnerability has a CVSS score of 7.5 (High), indicating a network-based attack with low complexity, requiring no user interaction, and primarily impacting availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE. Users are advised to upgrade to version v0.7.1 or higher, or implement custom unmarshaling methods to validate slice lengths.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.7.1CPE matchmatch criteria | cpe:2.3:a:binary_project:binary:*:*:*:*:*:go:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.