5 Total advisories
5 Vulnerabilities
0 Malware
Dependency scanning
Check whether com.github.junrar:junrar is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
LOW 3.7
CVE-2026-86071
Junrar: LocalFolderExtractor mkdir escape allows directory creation outside extraction root
HIGH 7.5
CVE-2022-23596
Junrar vulnerable to infinite loop via extracting carefully crafted RAR archive
MEDIUM 5.9
CVE-2026-41245
Junrar: Path Traversal (Zip-Slip) via Sibling Directory Name Prefix
MEDIUM 5.9
CVE-2026-28208
Junrar has an arbitrary file write due to backslash Path Traversal bypass in LocalFolderExtractor on Linux/Unix
MEDIUM 5.5
CVE-2018-12418
Junrar vulnerable to Infinite Loop
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes