JADX Project maintains a focused reverse-engineering and decompilation tool that analyzes Android applications and Java bytecode, with the vendor's limited disclosure footprint centered on the core JADX decompiler product. The observed weakness classes reflect its input-parsing role: improper input validation, improper restriction of XML external entity references, and related handling issues that arise in processing untrusted binary and markup artifacts. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jadx Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-39259MEDIUM jadx is a set of command line and GUI tools for producing Java source code from Android Dex and Apk files. versions prior to 1.4.5 are subject to a Denial of Service when opening z | Oct 21, 2022 | 5.5 | 16 | NO | NO |
CVE-2022-0219MEDIUM Improper Restriction of XML External Entity Reference in GitHub repository skylot/jadx prior to 1.3.2. | Jan 20, 2022 | 5.5 | 16 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jadx Project.
Media articles that mention a CVE ID that affects a product developed by Jadx Project — matched by CVE ID, not by vendor name.