Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-99087.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-99087
Upstream
Published
2026-09-03T19:17:31Z
Modified
2026-09-05T05:27:51Z
Summary
CVE-2026-85396 affecting package rubygem-rubyzip 2.3.2-1
Details

rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries with names like ../upload_backup/owned.sh to write files outside the intended extraction directory into sibling paths sharing the destination prefix.

References

Affected packages

Azure Linux:3 / rubygem-rubyzip

Package

Name
rubygem-rubyzip
Purl
pkg:rpm/azure-linux/rubygem-rubyzip

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
2.3.2-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-99087.json"