๐Ÿ” CVE Alert

CVE-2026-40180

UNKNOWN 0.0

Zip Slip Path Traversal in quarkus-openapi-generator ApicurioCodegenWrapper class

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
13th

Quarkus OpenAPI Generator is Quarkus' extensions for generation of Rest Clients and server stubs generation. Prior to 2.16.0 and 2.15.0-lts, the unzip() method in ApicurioCodegenWrapper.java extracts ZIP entries without validating that the resolved file path stays within the intended output directory. At line 101, the destination is constructed as new File(toOutputDir, entry.getName()) and the content is written immediately. A malicious ZIP archive containing entries with path traversal sequences (e.g., ../../malicious.java) would write files outside the target directory. This vulnerability is fixed in 2.16.0 and 2.15.0-lts.

CWE CWE-22
Vendor quarkiverse
Product quarkus-openapi-generator
Published Apr 10, 2026
Last Updated Apr 13, 2026
Stay Ahead of the Next One

Get instant alerts for quarkiverse quarkus-openapi-generator

Be the first to know when new unknown vulnerabilities affecting quarkiverse quarkus-openapi-generator are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

quarkiverse / quarkus-openapi-generator
< 2.15.0-lts < 2.16.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/quarkiverse/quarkus-openapi-generator/security/advisories/GHSA-jx2w-vp7f-456q github.com: https://github.com/quarkiverse/quarkus-openapi-generator/commit/08b406414ff30ed192e86c7fa924e57565534ff0 github.com: https://github.com/quarkiverse/quarkus-openapi-generator/commit/e2a9c629a3df719abc74569a3795c265fd0e1239