zip vulnerabilities
CVEs whose affected-version data names the zip package (rust). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2025-29787Highzip Incorrectly Canonicalizes Paths during Archive Extraction Leading to Arbitrary File Write
zip Incorrectly Canonicalizes Paths during Archive Extraction Leading to Arbitrary File Write
▾ Twilightzip · zipEPSS 0.56%via OSV
CVE-2018-13410Critical· 9.8PoCInfo-ZIP Zip 3.0, when the -T and -TT command-line options are used, allows attackers to cause a denial of service (invalid free and application crash) or possibly have unspecified other impact because of an off-by-one error
Info-ZIP Zip 3.0, when the -T and -TT command-line options are used, allows attackers to cause a denial of service (invalid free and application crash) or possibly have unspecified other impact because of an off-by-one error. NOTE: it is…
▾ Abyssalinfo-zip_project · zipEPSS 3.3%via NVD