Zip4j is a compact, specialized library for ZIP archive manipulation in Java applications, where its disclosures cluster around input-handling and path-traversal issues rooted in archive parsing and extraction logic. The recurring weakness classes—improper handling of exceptional conditions, path-traversal vulnerabilities during decompression, and origin-validation gaps—reflect the inherent complexity of safely processing untrusted archive structures; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zip4j Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1002202MEDIUM zip4j before 1.3.3 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during e | Jul 25, 2018 | 6.5 | 27 | NO | NO |
CVE-2023-22899MEDIUM Zip4j through 2.11.2, as used in Threema and other products, does not always check the MAC when decrypting a ZIP archive. | Jan 10, 2023 | 5.9 | 21 | NO | NO |
CVE-2022-24615MEDIUM zip4j up to v2.10.0 can throw various uncaught exceptions while parsing a specially crafted ZIP file, which could result in an application crash. This could be used to mount a deni | Feb 24, 2022 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zip4j Project.
Media articles that mention a CVE ID that affects a product developed by Zip4j Project — matched by CVE ID, not by vendor name.