Skip to content

[GHSA-gmq8-994r-jv83] yauzl contains an off-by-one error#7168

Open
adalinesimonian wants to merge 1 commit intoadalinesimonian/advisory-improvement-7168from
adalinesimonian-GHSA-gmq8-994r-jv83
Open

[GHSA-gmq8-994r-jv83] yauzl contains an off-by-one error#7168
adalinesimonian wants to merge 1 commit intoadalinesimonian/advisory-improvement-7168from
adalinesimonian-GHSA-gmq8-994r-jv83

Conversation

@adalinesimonian
Copy link

Updates

  • Affected products
  • CVSS v3

Comments
3.2.0 is the only version with the bug as it is the version where the vulnerable code was introduced. This CVE does not apply to any other version of yauzl. The current version range is resulting in numerous usages of non-vulnerable versions of yauzl getting flagged.

Copilot AI review requested due to automatic review settings March 14, 2026 21:08
@github-actions github-actions bot changed the base branch from main to adalinesimonian/advisory-improvement-7168 March 14, 2026 21:09
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants