Decoding malformed CAR data can cause panics or excessive memory usage.
{ "review_status": "REVIEWED", "url": "https://pkg.go.dev/vuln/GO-2022-0503" }
{ "imports": [ { "path": "github.com/ipld/go-car" }, { "path": "github.com/ipld/go-car/util" } ] }
{ "imports": [ { "path": "github.com/ipld/go-car/v2" }, { "path": "github.com/ipld/go-car/v2/blockstore" }, { "path": "github.com/ipld/go-car/v2/index" } ] }