VYPR
Moderate severityNVD Advisory· Published Oct 21, 2022· Updated Apr 22, 2025

Jadx-gui subject to Denial of Service via Swing HTML rendering

CVE-2022-39259

Description

jadx is a set of command line and GUI tools for producing Java source code from Android Dex and Apk files. versions prior to 1.4.5 are subject to a Denial of Service when opening zip files with HTML sequences. This issue has been patched in version 1.4.5. There are no known workarounds.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
io.github.skylot:jadx-plugins-apiMaven
< 1.4.51.4.5

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.