CVE Vulnerabilities

CVE-2026-105050

Incorrect Behavior Order: Validate Before Canonicalize

Published: Oct 02, 2026 | Modified: Oct 02, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

PeaZip before 11.3.0, in a non-default configuration, is vulnerable to OS command injection via a filename in an archive because quotation character already used in the string is mishandled.

Weakness

The product validates input before it is canonicalized, which prevents the product from detecting data that becomes invalid after the canonicalization step.

Potential Mitigations

References