PT-2026-41615 · Julia · Gccbootstrap Jll+2
Published
2026-05-07
·
Updated
2026-05-07
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in
zipOpenNewFileInZip4 64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gccbootstrap Jll
Openresty Jll
Zlib Jll