Rarlab maintains a focused but deeply embedded compression utility portfolio centered on WinRAR and the underlying unrar library, products whose presence in countless enterprise and consumer systems belies their narrow product count. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, have an elevated tendency toward confirmed in-the-wild exploitation and CISA KEV cataloging, and frequently acquire public exploit code, reflecting the appeal of archive-handling flaws for reliable remote code execution. The exposure recurs through a combination of memory-safety weaknesses—including out-of-bounds reads and writes, buffer over-runs, and improper bounds checking—and path-traversal conditions that arise from the parser's handling of archive entries, both classes with a long history of weaponization in the wild. Defenders should treat Rarlab advisories with urgency and prioritize patching, particularly for internet-facing or email-gateway contexts where archive processing is common; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rarlab over time
Signals from CVEs in this vendor scope (46 CVEs).
46 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-20250HIGH In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field i | Feb 5, 2019 | 7.8 | 98 | YES | YES |
CVE-2023-38831HIGH RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may inc | Aug 23, 2023 | 7.8 | 97 | YES | YES |
CVE-2022-30333HIGH RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_ke | May 9, 2022 | 7.5 | 97 | YES | YES |
CVE-2025-8088HIGH A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was ex | Aug 8, 2025 | 8.8 | 96 | YES | NO |
CVE-2025-6218HIGH RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinR | Jun 21, 2025 | 7.8 | 94 | YES | NO |
CVE-2004-1254HIGH WinRAR 3.40, and possibly earlier versions, allows remote attackers to execute arbitrary code via a ZIP file containing a file with a long filename, possibly causing an integer ove | Jan 10, 2005 | 10.0 | 46 | NO | YES |
CVE-2014-125119HIGH A filename spoofing vulnerability exists in WinRAR when opening specially crafted ZIP archives. The issue arises due to inconsistencies between the Central Directory and Local File | Jul 25, 2025 | 8.4 | 42 | NO | YES |
CVE-2006-3845HIGH Stack-based buffer overflow in lzh.fmt in WinRAR 3.00 through 3.60 beta 6 allows remote attackers to execute arbitrary code via a long filename in a LHA archive. | Jul 25, 2006 | 9.3 | 38 | NO | YES |
CVE-2012-6706CRITICAL A VMSF_DELTA memory corruption was discovered in unrar before 5.5.5, as used in Sophos Anti-Virus Threat Detection Engine before 3.37.2 and other products, that can lead to arbitra | Jun 22, 2017 | 9.8 | 35 | NO | NO |
CVE-2022-43650HIGH This vulnerability allows remote attackers to disclose sensitive information on affected installations of RARLAB WinRAR 6.11.0.0. User interaction is required to exploit this vulne | Mar 29, 2023 | 7.1 | 34 | NO | NO |
Signals from CVEs in this vendor scope (46 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rarlab.
Media articles that mention a CVE ID that affects a product developed by Rarlab — matched by CVE ID, not by vendor name.