Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/Ackites/KillWxapkg
  4. ›
  5. CVE-2025-5031

CVE-2025-5031: Ackites KillWxapkg Zip Bomb Resource Exhaustion

May 21, 2025

A vulnerability was found in Ackites KillWxapkg up to 2.4.1. It has been rated as problematic. This issue affects some unknown processing of the component wxapkg File Decompression Handler. The manipulation leads to resource consumption. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.

References

  • github.com/Ackites/KillWxapkg
  • github.com/Ackites/KillWxapkg/issues/86
  • github.com/advisories/GHSA-pqqp-7cp8-vxvf
  • nvd.nist.gov/vuln/detail/CVE-2025-5031
  • vuldb.com/?ctiid.309851
  • vuldb.com/?id.309851
  • vuldb.com/?submit.580524

Code Behaviors & Features

Detect and mitigate CVE-2025-5031 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions up to 1.1.0

Solution

Unfortunately, there is no solution available yet.

Impact 3.1 LOW

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L

Learn more about CVSS

Weakness

  • CWE-400: Uncontrolled Resource Consumption

Source file

go/github.com/Ackites/KillWxapkg/CVE-2025-5031.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 19 Aug 2025 12:19:01 +0000.