Executive brief
The iskorotkov/avro library, a high-performance Go-based tool for processing Avro data, is vulnerable to a denial-of-service attack. An attacker can send a specially crafted data payload that causes the library to enter an extremely long processing loop, effectively freezing the application and consuming 100% of a CPU core. This can lead to service outages or system crashes if multiple malicious requests are processed simultaneously.
Technical details
The vulnerability exists in the Avro array and map decoders within `codec_skip.go` and `reader_generic.go`. When decoding blocks, the library reads an attacker-controlled block-count value (up to math.MaxInt64) and iterates that many times. If the underlying reader encounters an error (such as EOF from a truncated payload), the inner decoder short-circuits, but the outer loop continues to iterate without checking the reader's error state. On 64-bit systems, this results in up to 9.2 quintillion no-op iterations, pinning a CPU core indefinitely. The issue is fixed in version 2.33.0 by adding an error check inside the loop body to terminate execution immediately upon the first inner-decode failure.
Affected products
- iskorotkov avro/v2 < 2.33.0
- hamba avro/v2 <= 2.31.0
Timeline
- 2026-05-11: advisory: GitHub Security Advisory published by iskorotkov
- 2026-05-29: disclosed: CVE-2026-46385 published to NVD