Rubyzipproject Rubyzip
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Rubyzipproject Rubyzip.
By the Year
In 2026 there have been 1 vulnerability in Rubyzipproject Rubyzip with an average score of 8.7 out of ten. Rubyzip did not have any published security vulnerabilities last year. That is, 1 more vulnerability have already been reported in 2026 as compared to last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 1 | 8.70 |
| 2025 | 0 | 0.00 |
| 2024 | 0 | 0.00 |
| 2023 | 0 | 0.00 |
| 2022 | 0 | 0.00 |
| 2021 | 0 | 0.00 |
| 2020 | 0 | 0.00 |
| 2019 | 1 | 0.00 |
| 2018 | 1 | 9.80 |
It may take a day or so for new Rubyzip vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Rubyzipproject Rubyzip Security Vulnerabilities
RubyZip <3.4.0 Path Traversal via Zip::Entry#extract
CVE-2026-85396
8.7 - High
- September 03, 2026
rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries with names like ../upload_backup/owned.sh to write files outside the intended extraction directory into sibling paths sharing the destination prefix.
Directory traversal
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes
CVE-2019-16892
- September 25, 2019
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption).
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component
CVE-2018-1000544
9.8 - Critical
- June 26, 2018
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem..
insecure temporary file
The Zip::File component in the rubyzip gem before 1.2.1 for Ruby has a directory traversal vulnerability
CVE-2017-5946
- February 27, 2017
The Zip::File component in the rubyzip gem before 1.2.1 for Ruby has a directory traversal vulnerability. If a site allows uploading of .zip files, an attacker can upload a malicious file that uses "../" pathname substrings to write arbitrary files to the filesystem.
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Rubyzipproject Rubyzip or by Rubyzipproject? Click the Watch button to subscribe.