{"id":"CVE-2026-40180","summary":"Zip Slip Path Traversal in quarkus-openapi-generator ApicurioCodegenWrapper class","details":"Quarkus OpenAPI Generator is Quarkus' extensions for generation of Rest Clients and server stubs generation. Prior to 2.16.0 and 2.15.0-lts, the unzip() method in ApicurioCodegenWrapper.java extracts ZIP entries without validating that the resolved file path stays within the intended output directory. At line 101, the destination is constructed as new File(toOutputDir, entry.getName()) and the content is written immediately. A malicious ZIP archive containing entries with path traversal sequences (e.g., ../../malicious.java) would write files outside the target directory. This vulnerability is fixed in 2.16.0 and 2.15.0-lts.","aliases":["GHSA-jx2w-vp7f-456q"],"modified":"2026-08-12T16:24:02.253169Z","published":"2026-04-10T19:35:53.440Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-22"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40180.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40180.json"},{"type":"ADVISORY","url":"https://github.com/quarkiverse/quarkus-openapi-generator/security/advisories/GHSA-jx2w-vp7f-456q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40180"},{"type":"FIX","url":"https://github.com/quarkiverse/quarkus-openapi-generator/commit/08b406414ff30ed192e86c7fa924e57565534ff0"},{"type":"FIX","url":"https://github.com/quarkiverse/quarkus-openapi-generator/commit/e2a9c629a3df719abc74569a3795c265fd0e1239"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/quarkiverse/quarkus-openapi-generator","events":[{"introduced":"0"},{"fixed":"59cc68f30c6b29bb68841bb5d199875d7af3956c"},{"introduced":"59cc68f30c6b29bb68841bb5d199875d7af3956c"},{"fixed":"08b406414ff30ed192e86c7fa924e57565534ff0"},{"fixed":"e2a9c629a3df719abc74569a3795c265fd0e1239"}],"database_specific":{"cpe":["cpe:2.3:a:quarkiverse:quarkus_openapi_generator:*:*:*:*:*:*:*:*","cpe:2.3:a:quarkiverse:quarkus_openapi_generator:2.15.0:*:*:*:-:*:*:*"],"extracted_events":[{"introduced":"0"},{"fixed":"2.15.0"},{"introduced":"2.15.0"},{"last_affected":"2.15.0"}],"source":["CPE_RANGE","CPE_STRING","REFERENCES"]}}],"versions":["2.15.0","2.11.0-lts","2.14.0","2.14.0-lts","2.13.0-lts","2.13.0","2.12.1","2.12.1-lts","2.12.0-lts","2.12.0","2.11.0","2.10.0","2.10.0-lts","2.9.1-lts","2.9.0-lts","2.9.0","2.8.2-lts","2.8.2","2.8.1-lts","2.8.1","2.4.7","2.8.0-lts","2.8.0","2.7.1-lts","2.7.1","2.7.0-lts","2.7.0","2.6.0-lts","2.6.0","2.5.0","2.4.6","2.4.2","2.4.1","2.4.0","2.3.0","2.2.16","2.2.15","2.2.14","2.2.13","2.2.12","2.2.11","2.2.10","2.2.9","2.2.8","2.2.7","2.2.6","2.2.5","2.2.4","2.2.2","2.2.1","2.2.0","2.1.1","2.1.0","2.0.0","1.0.1","1.0.0","0.12.0","0.11.0","0.10.0","0.9.0","0.8.0","0.7.0","0.6.1","0.6.0","0.5.0","0.4.1","0.4.0","0.3.1","0.2.0","0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40180.json","vanir_signatures_modified":"2026-08-12T16:24:02Z","vanir_signatures":[{"id":"CVE-2026-40180-06d12a8c","signature_type":"Function","signature_version":"v1","source":"https://github.com/quarkiverse/quarkus-openapi-generator/commit/08b406414ff30ed192e86c7fa924e57565534ff0","target":{"file":"server/deployment/src/main/java/io/quarkiverse/openapi/server/generator/deployment/codegen/apicurio/ApicurioCodegenWrapper.java","function":"unzip"},"deprecated":false,"digest":{"function_hash":"18784357138877532791092538751541877431","length":590}},{"deprecated":false,"digest":{"function_hash":"18784357138877532791092538751541877431","length":590},"id":"CVE-2026-40180-607a01ad","signature_type":"Function","signature_version":"v1","source":"https://github.com/quarkiverse/quarkus-openapi-generator/commit/e2a9c629a3df719abc74569a3795c265fd0e1239","target":{"file":"server/deployment/src/main/java/io/quarkiverse/openapi/server/generator/deployment/codegen/apicurio/ApicurioCodegenWrapper.java","function":"unzip"}},{"deprecated":false,"digest":{"line_hashes":["202421988604829047183145106643449323815","238622307040447926593883545770932295635","73823340916274474249862482991648674769","274017534119256623341375702549666991277","235702852362489078004508937082245866558","225455587559534490760028249835156141731","29379100023841792764398212304806267348","317775865703317987894002029904311040498","16202098862095557454427731262995397438","106223154189834772214023930769822604677"],"threshold":0.9},"id":"CVE-2026-40180-6ff0b991","signature_type":"Line","signature_version":"v1","source":"https://github.com/quarkiverse/quarkus-openapi-generator/commit/e2a9c629a3df719abc74569a3795c265fd0e1239","target":{"file":"server/deployment/src/main/java/io/quarkiverse/openapi/server/generator/deployment/codegen/apicurio/ApicurioCodegenWrapper.java"}},{"deprecated":false,"digest":{"line_hashes":["202421988604829047183145106643449323815","238622307040447926593883545770932295635","73823340916274474249862482991648674769","274017534119256623341375702549666991277","235702852362489078004508937082245866558","225455587559534490760028249835156141731","29379100023841792764398212304806267348","317775865703317987894002029904311040498","16202098862095557454427731262995397438","106223154189834772214023930769822604677"],"threshold":0.9},"id":"CVE-2026-40180-d834cf72","signature_type":"Line","signature_version":"v1","source":"https://github.com/quarkiverse/quarkus-openapi-generator/commit/08b406414ff30ed192e86c7fa924e57565534ff0","target":{"file":"server/deployment/src/main/java/io/quarkiverse/openapi/server/generator/deployment/codegen/apicurio/ApicurioCodegenWrapper.java"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P"}]}