Loading HuntDB...

GHSA-236w-p7wf-5ph8

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors.

Related CVEs

Key Information

GHSA ID
GHSA-236w-p7wf-5ph8
Published
June 5, 2024 6:30 PM
Last Modified
January 31, 2025 3:30 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 18, 2025 6:27 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.