pf4j is vulnerable to Path Traversal or Zip Slip attack through improper handling of zip entry names
High severity
GitHub Reviewed
Published
Mar 25, 2026
to the GitHub Advisory Database
•
Updated Mar 27, 2026
Description
Published by the National Vulnerability Database
Mar 25, 2026
Published to the GitHub Advisory Database
Mar 25, 2026
Reviewed
Mar 27, 2026
Last updated
Mar 27, 2026
pf4j before 20c2f80 has a path traversal vulnerability in the extract() function of Unzip.java, where improper handling of zip entry names can allow directory traversal or Zip Slip attacks, due to a lack of proper path normalization and validation.
References