CVE-2025-0851: Aws Deepjavalibrary

Critical severity, CVSS 9.8. EPSS: 23.3% chance of exploitation in the next 30 days.

A path traversal issue in ZipUtils.unzip and TarUtils.untar in Deep Java Library (DJL) on all platforms allows a bad actor to write files to arbitrary locations.

Affected products

  • Aws Deepjavalibrary: from 0.1.0, before 0.31.1 (fixed in 0.31.1)

Published 2025-01-29. Last modified 2026-06-17.