Ziparchive Project maintains a focused archive-handling library whose vulnerability footprint centers on file extraction and path processing, with a recurring pattern of improper exception handling, path-traversal conditions, and symlink-following weaknesses that are characteristic of archive parsers. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ziparchive Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-36943HIGH SSZipArchive versions 2.5.3 and older contain an arbitrary file write vulnerability due to lack of sanitization on paths which are symlinks. SSZipArchive will overwrite files on th | Jan 3, 2023 | 8.1 | 26 | NO | NO |
CVE-2023-39136MEDIUM An unhandled edge case in the component _sanitizedPath of ZipArchive v2.5.4 allows attackers to cause a Denial of Service (DoS) via a crafted zip file. | Aug 30, 2023 | 5.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ziparchive Project.
Media articles that mention a CVE ID that affects a product developed by Ziparchive Project — matched by CVE ID, not by vendor name.