Sharpziplib is a widely embedded compression and archive library for the .NET platform that, despite a narrow product footprint, reaches into numerous downstream applications through its core ZIP handling functionality. The library's vulnerability surface is characterized by path-traversal weaknesses in archive extraction, a persistent risk class in decompression utilities that can enable directory-escape attacks when downstream consumers fail to validate extracted file paths. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sharpziplib Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-32840CRITICAL SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Prior to version 1.3.3, a TAR file entry `../evil.txt` may be extracted in the parent directory of `destFolder`. Thi | Jan 26, 2022 | 9.8 | 32 | NO | NO |
CVE-2018-1002208MEDIUM SharpZipLib before 1.0 RC1 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled | Jul 25, 2018 | 5.5 | 24 | NO | NO |
CVE-2021-32841MEDIUM SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Starting version 1.3.0 and prior to version 1.3.3, a check was added if the destination file is under destination di | Jan 26, 2022 | 5.3 | 20 | NO | NO |
CVE-2021-32842MEDIUM SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Starting version 1.0.0 and prior to version 1.3.3, a check was added if the destination file is under a destination | Jan 26, 2022 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sharpziplib Project.
Media articles that mention a CVE ID that affects a product developed by Sharpziplib Project — matched by CVE ID, not by vendor name.