Medium severity5.5NVD Advisory· Published Aug 30, 2023· Updated Jun 17, 2026
CVE-2023-39136
CVE-2023-39136
Description
An unhandled edge case in the component _sanitizedPath of ZipArchive v2.5.4 allows attackers to cause a Denial of Service (DoS) via a crafted zip file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:ziparchive_project:ziparchive:2.5.4:*:*:*:*:*:*:*
- ZipArchive/ZipArchivedescription
- Range: <2.5.4
Patches
Vulnerability mechanics
References
4- blog.ostorlab.co/zip-packages-exploitation.htmlnvdExploitThird Party Advisory
- github.com/ZipArchive/ZipArchive/issues/680nvdExploitIssue TrackingPatchVendor Advisory
- ostorlab.co/vulndb/advisory/OVE-2023-2nvdExploitThird Party Advisory
- security.snyk.io/research/zip-slip-vulnerabilitynvdThird Party Advisory
News mentions
0No linked articles in our index yet.