Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-x2xq-qhjf-5mvg | DDEV has ZipSlip path traversal in tar and zip archive extraction |
Mon, 11 May 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:ddev:ddev:*:*:*:*:*:*:*:* |
Mon, 27 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ddev
Ddev ddev |
|
| Vendors & Products |
Ddev
Ddev ddev |
Wed, 22 Apr 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 22 Apr 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DDEV is an open-source tool for running local web development environments for PHP and Node.js. Versions prior to 1.25.2 have unsanitized extraction in both `Untar()` and `Unzip()` functions in `pkg/archive/archive.go`. Downloads and extracts archives from remote sources without path validation. Version 1.25.2 patches the issue. | |
| Title | DDEV has ZipSlip path traversal in tar and zip archive extraction | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-22T18:35:36.170Z
Reserved: 2026-03-16T21:03:44.421Z
Link: CVE-2026-32885
Updated: 2026-04-22T18:18:57.479Z
Status : Analyzed
Published: 2026-04-22T17:16:34.770
Modified: 2026-05-11T20:33:24.183
Link: CVE-2026-32885
No data.
OpenCVE Enrichment
Updated: 2026-04-27T19:53:21Z
Github GHSA