The `Reader.Open` API, new in Go 1.16, will panic when used on a ZIP archive containing files that start with “../”. This issue is CVE-2021-27919.
The
Reader.OpenAPI, new in Go 1.16, will panic when used on a ZIP archive containing files that start with “../”.This issue is CVE-2021-27919.