Microsoft Security Response Center guidance
Release Notes
Vulnerability intelligence
CVE-2026-63209 and is rated High severity with a CVSS score of 7.5. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
Release Notes
compress provides various compression algorithms. Prior to version 1.18.7, a signed integer overflow vulnerability in s2.NewDict() allows an attacker to bypass repeat index validation by supplying a dictionary with a uvarint-encoded repeat value exceeding MaxInt64. When Dict.Encode() is subsequently called, the overflowed negative repeat value causes an out-of-bounds memory access via unsafe.Pointer arithmetic, crashing the process with SIGSEGV. This issue has been patched in version 1.18.7.