Libzip is a widely embedded C library for reading, creating, and modifying ZIP archives, deployed across numerous applications and platforms despite a narrow direct product scope. Its vulnerability profile centers on resource-management and memory-safety issues—including resource exhaustion without throttling, double-free conditions, and use-after-free flaws—characteristic of low-level C implementations handling untrusted archive data. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libzip over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-12858CRITICAL Double free vulnerability in the _zip_dirent_read function in zip_dirent.c in libzip allows attackers to have unspecified impact via unknown vectors. | Aug 23, 2017 | 9.8 | 32 | NO | NO |
CVE-2019-17582CRITICAL A use-after-free in the _zip_dirent_read function of zip_dirent.c in libzip 1.2.0 allows attackers to have an unspecified impact by attempting to unzip a malformed ZIP archive. NOT | Feb 9, 2021 | 9.8 | 29 | NO | NO |
CVE-2017-14107MEDIUM The _zip_read_eocd64 function in zip_open.c in libzip before 1.3.0 mishandles EOCD records, which allows remote attackers to cause a denial of service (memory allocation failure in | Sep 1, 2017 | 6.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libzip.
Media articles that mention a CVE ID that affects a product developed by Libzip — matched by CVE ID, not by vendor name.