CVE-2026-34743
Severity CVSS v4.0:
LOW
Type:
CWE-122
Heap-based Buffer Overflow
Publication date:
02/04/2026
Last modified:
15/04/2026
Description
XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3.
Impact
Base Score 4.0
1.70
Severity 4.0
LOW
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:tukaani:xz:*:*:*:*:*:*:*:* | 5.8.3 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



