CVE-2017-12940: RARLAB UnRAR
Critical severity, CVSS 9.8. EPSS: 2.2% chance of exploitation in the next 30 days.
libunrar.a in UnRAR before 5.5.7 has an out-of-bounds read in the EncodeFileName::Decode call within the Archive::ReadHeader15 function.
Affected products
- RARLAB UnRAR: up to and including 5.5.6
Published 2017-08-18. Last modified 2026-06-17.