V
Vexday
by TrueHacking
›
Briefing
Live
PT
ES
EN
Home
/
Technologies
/
zarf-dev
Vulnerabilities in
zarf-dev
2 results
CVE-2026-40090
HIGH
Zarf has a Path Traversal via Malicious Package Metadata.Name — Arbitrary File Write
EPSS
0.3%
CVE-2026-29064
HIGH
Zarf: Symlink targets in archives are not validated against destination directory
EPSS
0.2%