CVE-2026-65921
EUVD-2026-4956927.07.2026, 20:16
A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be written outside the intended build artifacts location.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| jfrog | artifactory | 𝑥 < 7.111.18 | CNA |
| jfrog | artifactory | 7.117.0 ≤ 𝑥 < 7.117.25 | CNA |
| jfrog | artifactory | 7.125.0 ≤ 𝑥 < 7.125.18 | CNA |
| jfrog | artifactory | 7.133.0 ≤ 𝑥 < 7.133.27 | CNA |
| jfrog | artifactory | 7.146.0 ≤ 𝑥 < 7.146.34 | CNA |
| jfrog | artifactory | 7.161.0 ≤ 𝑥 < 7.161.15 | CNA |