Junrar Project maintains a focused Java library for RAR archive extraction that, despite its narrow scope, sits within the supply chain of applications requiring archive-handling capability. The recurring vulnerability signal centers on path-traversal and infinite-loop conditions that arise in archive-parsing logic, reflecting the complexity inherent to decompression formats and the risk of malformed or malicious archive content.
The number and severity of CVEs published that impact products developed by Junrar Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-41245HIGH Junrar is an open source java RAR archive library. Prior to version 7.5.10, a path traversal vulnerability in `LocalFolderExtractor` allows an attacker to write arbitrary files wit | Apr 20, 2026 | 7.5 | 27 | NO | NO |
CVE-2026-28208MEDIUM Junrar is an open source java RAR archive library. Prior to version 7.5.8, a backslash path traversal vulnerability in `LocalFolderExtractor` allows an attacker to write arbitrary | Feb 26, 2026 | 5.9 | 27 | NO | NO |
CVE-2022-23596HIGH Junrar is an open source java RAR archive library. In affected versions A carefully crafted RAR archive can trigger an infinite loop while extracting said archive. The impact depen | Feb 1, 2022 | 7.5 | 25 | NO | NO |
CVE-2018-12418MEDIUM Archive.java in Junrar before 1.0.1, as used in Apache Tika and other products, is affected by a denial of service vulnerability due to an infinite loop when handling corrupt RAR f | Jun 14, 2018 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Junrar Project.
Media articles that mention a CVE ID that affects a product developed by Junrar Project — matched by CVE ID, not by vendor name.