CVE-2024-3094: Critical backdoor in xz-utils 5.6.0
The xz-utils package version 5.6.0-5.6.1 contains a malicious backdoor that compromises SSH authentication on affected systems.
CWE
CWE-506
CVE
CVE-2024-3094
OWASP
N/A
CVSS Score
10.0
Source
SCA
Category
Vulnerable Dependency
Exploitability
ActivelyExploited
Detected
2026-05-25 19:02
Code Location
// No code snippet available for this finding.
AI Explanation
This is an actively exploited vulnerability with a CVSS score of 10.0. Immediate patching is required.
Remediation Suggestion
Downgrade xz-utils to 5.4.x or upgrade to 5.6.2+.
Related Findings
| Severity | Title | CWE | Status |
|---|---|---|---|
High |
CVE-2023-44487: HTTP/2 Rapid Reset denial of service | CWE-400 | Resolved |
Change Status