| Release | Version |
|---|---|
| bookworm | 2.0.1+ds-4 |
| trixie | 2.0.1+ds-4 |
| forky | 2.0.1+ds-4 |
| sid | 2.0.1+ds-4 |
| Bug | bookworm | trixie | forky | sid | Description |
|---|---|---|---|---|---|
| CVE-2026-56876 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | vulnerable | vulnerable | extract-zip does not validate symlink targets when extracting zip arch ... |
| CVE-2026-19693 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | vulnerable | vulnerable | extract-zip through 2.0.1 containment-checks only the parent directory ... |