Junrar Project
Junrar Project Junrar: vulnerabilities and CVEs
Junrar Project Junrar has 4 published vulnerabilities, 2 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs4
Last 12 months2
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41245 | High (7.5) | 0.53% | — | Apr 20, 2026 | Junrar is an open source java RAR archive library. Prior to version 7.5.10, a path traversal vulnerability in `LocalFolderExtractor` allows an attacker to write arbitrary files with attacker-controlled content into… |
| CVE-2026-28208 | Medium (5.9) | 0.75% | — | Feb 26, 2026 | Junrar is an open source java RAR archive library. Prior to version 7.5.8, a backslash path traversal vulnerability in `LocalFolderExtractor` allows an attacker to write arbitrary files with attacker-controlled content… |
| CVE-2022-23596 | High (7.5) | 1.6% | — | Feb 1, 2022 | Junrar is an open source java RAR archive library. In affected versions A carefully crafted RAR archive can trigger an infinite loop while extracting said archive. The impact depends solely on how the application uses… |
| CVE-2018-12418 | Medium (5.5) | 1.2% | — | Jun 14, 2018 | Archive.java in Junrar before 1.0.1, as used in Apache Tika and other products, is affected by a denial of service vulnerability due to an infinite loop when handling corrupt RAR files. |