{"id":"RUSTSEC-2026-0296","title":"`unzip` is unmaintained","summary":"`unzip` is unmaintained","severity":"none","vendor":"unzip","product":"unzip","ecosystem":"rust","affected":["unzip >= 0.0.0-0"],"published":"2026-09-21","updated":"2026-09-21","sourceUpdated":"2026-09-21T15:30:02.903397197Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/RUSTSEC-2026-0296","references":[{"url":"https://crates.io/crates/unzip"},{"url":"https://rustsec.org/advisories/RUSTSEC-2026-0296.html"},{"url":"https://crates.io/crates/unzip"}],"tags":["osv","rust"],"ingestedAt":"2026-09-21T16:28:35.401Z","slug":"RUSTSEC-2026-0296","body":"## Overview\n\nThe [unzip](https://crates.io/crates/unzip) crate has only ever released a single\nversion, `0.1.0` (published 2017-12-23), and has seen no further activity. It\nappears to be unmaintained, and its known path-traversal (\"zip-slip\")\nvulnerability will not be fixed.\n\nConsider migrating to an actively maintained alternative such as\n[zip](https://crates.io/crates/zip).\n\n## Affected packages\n\n- `unzip >= 0.0.0-0`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}