CVE-2024-3094
CRITICAL 10.0EPSS 86.0%
Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library.
- CVSS v3.1
- 10.0 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H - CVSS v3.1
- 10.0 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H - EPSS
- 85.97% chance of exploitation in the next 30 days, 100th percentile
- Nuclei
- critical · CWE-506
- Published
- 2024-03-29
- Updated
- 2026-08-04
Proof-of-concept exploits (46)
- 0xlane/xz-cve-2024-309417★ · 2024-04-02
- 24Owais/threat-intel-cve-2024-30941★ · 2025-06-19
- Fractal-Tess/CVE-2024-30940★ · 2024-03-30
- Horizon-Software-Development/CVE-2024-30942★ · 2024-03-30
- MagpieRYL/CVE-2024-3094-backdoor-env-container0★ · 2024-04-03
- MrBUGLF/XZ-Utils_CVE-2024-30940★ · 2024-04-01
- Mustafa1986/CVE-2024-30940★ · 2024-04-01
- OpensourceICTSolutions/xz_utils-CVE-2024-30940★ · 2024-03-29
- ScrimForever/CVE-2024-30942★ · 2024-04-02
- Simplifi-ED/CVE-2024-3094-patcher0★ · 2024-03-31
- Yuma-Tsushima07/CVE-2024-30944★ · 2024-03-31
- ackemed/detectar_cve-2024-30940★ · 2024-04-01
- ashwani95/CVE-2024-30940★ · 2024-03-30
- been22426/CVE-2024-30940★ · 2025-04-16
- brinhosa/CVE-2024-3094-One-Liner1★ · 2024-04-01
- byinarie/CVE-2024-3094-info54★ · 2024-04-01
- dah4k/CVE-2024-30940★ · 2024-04-01
- felipecosta09/cve-2024-30944★ · 2024-04-05
- fevar54/Detectar-Backdoor-en-liblzma-de-XZ-utils-CVE-2024-3094-0★ · 2024-04-13
- gayatriracha/CVE-2024-3094-Nmap-NSE-script0★ · 2024-03-31
- gustavorobertux/CVE-2024-30943★ · 2024-04-02
- hiitaro/CVE-Searcher6★ · 2025-06-11
- isuruwa/CVE-2024-30940★ · 2024-03-31
- jfrog/cve-2024-3094-tools45★ · 2024-04-07
- mightysai1997/CVE-2024-30940★ · 2024-04-01
- mightysai1997/CVE-2024-3094-info0★ · 2024-04-01
- mightysai1997/xzbot0★ · 2024-04-05
- mrk336/CVE-2024-30941★ · 2025-09-12
- neuralinhibitor/xzwhy5★ · 2024-04-18
- pentestfunctions/CVE-2024-30943★ · 2024-04-02
- r0binak/xzk8s14★ · 2024-04-06
- shefirot/CVE-2024-30940★ · 2024-06-11
- teyhouse/CVE-2024-309411★ · 2024-03-31
- valeriot30/cve-2024-30941★ · 2025-06-06
- 0xBlackash/CVE-2024-3094
- FabioBaroni/CVE-2024-3094-checker
- Security-Phoenix-demo/CVE-2024-3094-fix-exploits
- ThomRgn/xzutils_backdoor_obfuscation
- extracoding-dozen/CVE-2024-3094
- h3raklez/CVE-2024-3094
- hackura/xz-cve-2024-3094
- vesjolyjd/Kaspersky_CVE-2024-3094
- vnchk1/sec_review_cve-2024-3094
- 0xbitx/rust_doc_hidden_poc
- Ol4dipo/Vulnerability-Mapper
- lime-green/xz-backdoor-repro