debian · CVE-2025-70952

Quick triage

Priority: not yet assigned Published: Updated: Wed, 22 Jul 2026 14:46:41 GMT

View at Official debian advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2025-70952 not yet assigned priority: Debian including 1 source packages (libpf4j-java), 3 status rows across 3 suites (bookworm, sid, trixie): open 3.

Description:

pf4j before 20c2f80 has a path traversal vulnerability in the extract() function of Unzip.java, where improper handling of zip entry names can allow directory traversal or Zip Slip attacks, due to a lack of proper path normalization and validation.

cvelogic Threat Intelligence