← Vulnerability feed

Vulnerability record · CVE-2022-24615 · published 24 February 2022

CVE-2022-24615: Zip4j project zip4j vulnerability

ZZip4j Project · Zip4j

zip4j up to v2.10.0 can throw various uncaught exceptions while parsing a specially crafted ZIP file, which could result in an application crash. This could be used to mount a denial of service attack against services that use zip4j library.

5.5 CVSS 3.1 Medium EPSS 0.71% · top 48.4% CWE-755 · CWE-755
5.5CVSS 3.1 base score, v2 4.3
0.71%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

zip4j up to v2.10.0 can throw various uncaught exceptions while parsing a specially crafted ZIP file, which could result in an application crash. This could be used to mount a denial of service attack against services that use zip4j library.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/srikanth-lingala/zip4j/issues/377 Issue TrackingThird Party Advisory
https://github.com/srikanth-lingala/zip4j/issues/418 Issue TrackingThird Party Advisory
https://github.com/srikanth-lingala/zip4j/issues/377 Issue TrackingThird Party Advisory
https://github.com/srikanth-lingala/zip4j/issues/418 Issue TrackingThird Party Advisory

Track CVE-2022-24615 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.5CVE-2018-1002202Zip4j project zip4j path traversal vulnerabilityzip4j before 1.3.3 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive en…EPSS 11%5.9CVE-2023-22899Zip4j project zip4j origin validation error vulnerabilityZip4j through 2.11.2, as used in Threema and other products, does not always check the MAC when decrypting a ZIP archive.EPSS 0.62%7.8CVE-2024-29748Android Pixel logic error allows local privilege escalationCVE-2024-29748 is a logic error in Android code that permits bypassing a security check, leading to local escalation of privilege. It affects Google …KEVEPSS 0.67%analysed9.8CVE-2020-7247OpenSMTPD MAIL FROM command injection allows remote root code executionOpenSMTPD 6.6, as shipped in OpenBSD 6.6 and other products, mishandles input validation in smtp_mailaddr in smtp_session.c, returning an incorrect v…KEVEPSS 99%analysed8.6CVE-2018-0155Cisco Catalyst BFD offload incomplete header handling denial of serviceCisco Catalyst 4500 and 4500-X series switches mishandle incomplete BFD headers in the BFD offload implementation, causing the iosd process to crash.…KEVEPSS 7.7%analysed8.8CVE-2021-38003Google Chrome V8 heap corruption via crafted HTML pageGoogle Chrome before 95.0.4638.69 contains an inappropriate implementation in the V8 JavaScript engine that can lead to heap corruption. A remote att…KEVEPSS 39%analysed9.8CVE-2017-5638Apache Struts 2 Jakarta Multipart parser remote code executionThe Jakarta Multipart parser in Apache Struts 2 mishandles exceptions and error messages during file-upload attempts, letting a crafted Content-Type,…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2022-24615), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.