Skip to content

Security: Upgrade rardecode v1 to v2 to mitigate DoS vulnerability (GO-2025-4020) #1279

@dgoro-backline

Description

@dgoro-backline

Summary

The jfrog-client-go library depends on github.com/nwaples/rardecode v1.1.3, which is affected by GO-2025-4020 - a DoS vulnerability due to unrestricted RAR dictionary sizes.

Current State

  • jfrog-client-go v1.55.0 still uses rardecode v1.1.3
  • The rardecode v1.x branch has no fix and appears unmaintained (last release: March 2022)
  • rardecode/v2 (v2.2.0+) introduced MaxDictionarySize() option to mitigate this issue

Dependency Path

github.com/jfrog/jfrog-client-go
  └── github.com/jfrog/archiver/v3
        └── github.com/nwaples/rardecode v1.1.3

Request

Could you please consider upgrading to github.com/nwaples/rardecode/v2 to address this vulnerability? This would allow downstream consumers to resolve the Dependabot/security scanner alerts.

References

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions