The Xz Project maintains a data-compression library widely embedded in Unix and Linux distributions, where its small product footprint belies its deep presence in critical system infrastructure. Observed vulnerabilities in this library center on control-flow issues such as infinite loops, reflecting the algorithmic complexity inherent to compression implementations. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xz Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-29482HIGH xz is a compression and decompression library focusing on the xz format completely written in Go. The function readUvarint used to read the xz container format may not terminate a | Apr 28, 2021 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xz Project.
Media articles that mention a CVE ID that affects a product developed by Xz Project — matched by CVE ID, not by vendor name.