CVE-2025-70952: PF4J Project PF4J
High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.
pf4j before 20c2f80 has a path traversal vulnerability in the extract() function of Unzip.java, where improper handling of zip entry names can allow directory traversal or Zip Slip attacks, due to a lack of proper path normalization and validation.
Affected products
- PF4J Project PF4J: before 3.14.1 (fixed in 3.14.1)
Published 2026-03-25. Last modified 2026-06-17.