CVE-2026-44088

SzafirHost verifies the signature of the downloaded JAR file using class JarInputStream (reading from the beginning of the file), but loads classes using class JarFile/URLClassLoader (reading the Central Directory from the end). It can lead to remote code execution by allowing an attacker to combine a genuine, signed JAR file with a malicious ZIP file, causing the verification to pass but the malicious class to be loaded. This issue was fixed in version 1.2.1.
CVSS

No CVSS.

Configurations

No configuration.

History

15 May 2026, 09:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-15 09:16

Updated : 2026-06-17 10:50


NVD link : CVE-2026-44088

Mitre link : CVE-2026-44088

CVE.ORG link : CVE-2026-44088


JSON object : View

Products Affected

No product.

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type