Known Vulnerabilities for Unzip by Unzip Project
Listed below are 10 of the newest known vulnerabilities associated with "Unzip" by "Unzip Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-48959 json | IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward. fastForward... | Not Provided | 2026-05-27 | 2026-05-29 |
| CVE-2026-44257 json | efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, efw.file.FileManager.unZip writes zip entries to disk using new... | Not Provided | 2026-05-12 | 2026-05-18 |
| CVE-2026-40180 json | Quarkus OpenAPI Generator is Quarkus' extensions for generation of Rest Clients and server stubs generation. Prior to 2.16.0 ... | Not Provided | 2026-04-10 | 2026-04-13 |
| CVE-2026-32885 json | DDEV is an open-source tool for running local web development environments for PHP and Node.js. Versions prior to 1.25.2 have... | Not Provided | 2026-04-22 | 2026-04-22 |
| CVE-2025-70952 json | pf4j before 20c2f80 has a path traversal vulnerability in the extract() function of Unzip.java, where improper handling of zi... | Not Provided | 2026-03-25 | 2026-03-28 |
| CVE-2025-15649 json | IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS ... | Not Provided | 2026-05-27 | 2026-05-29 |
| CVE-2025-4748 json | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP (stdlib modules) a... | Not Provided | 2025-06-16 | 2026-04-06 |
| CVE-2024-36057 json | Koha Library before 23.05.10 fails to sanitize user-controllable filenames prior to unzipping, leading to remote code executi... | Not Provided | 2026-04-07 | 2026-04-09 |
| CVE-2022-0530 json | A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a ... | 5.5 - MEDIUM | 2022-02-09 | 2023-11-09 |
| CVE-2022-0529 json | A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a ... | 5.5 - MEDIUM | 2022-02-09 | 2023-11-09 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Unzip Project | Unzip | 6.0 | |||
| Application | Unzip Project | Unzip | 5.52 | |||
| Application | Unzip Project | Unzip | 5.51 |