๐Ÿ” CVE Alert

CVE-2025-70952

HIGH 7.5
CVSS Score
7.5
EPSS Score
0.1%
EPSS Percentile
17th

pf4j before 20c2f80 has a path traversal vulnerability in the extract() function of Unzip.java, where improper handling of zip entry names can allow directory traversal or Zip Slip attacks, due to a lack of proper path normalization and validation.

Vendor n/a
Product n/a
Published Mar 25, 2026
Last Updated Mar 28, 2026
Stay Ahead of the Next One

Get instant alerts for n/a n/a

Be the first to know when new high vulnerabilities affecting n/a n/a are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

n/a / n/a
n/a

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/pf4j/pf4j/issues/618 github.com: https://github.com/pf4j/pf4j/issues/623 github.com: https://github.com/pf4j/pf4j/commit/20c2f80089d1ea779e22c2de5f109a0bce4e1b14 gist.github.com: https://gist.github.com/weaver4VD/410f23adb24ef5f5077f021f4393e705