VU#976247: Antivirus and Endpoint Detection and Response Archive Scanning Engines may not properly scan malformed zip archives

2026-03-09T20:52:12Za0f31412a4a4c0c564313e4c27eada7646b25494d534adc7af7e15d8f72f7e43
antivirus-evasionarbitrary-file-writearchive-evasionauthentication-bypassc/c++code-injectioncommand-injectiondeep-packet-inspectiondenial-of-serviceedr-evasionhardcoded-secretsimage-decoderjwtnodejsopen5gsout-of-boundspath-traversalpdf-libraryprototype-pollutionpythonrcetls-fingerprintviberwebuizip

What happened

This collection of vulnerability notes covers multiple distinct issues across open-source libraries and applications: archive-scanning evasion via malformed ZIP metadata that can hide payloads from antivirus/EDR engines; a TLS handshake fingerprinting flaw in Rakuten Viber’s Cloak proxy (identifiable via DPI); command-injection (RCE) in the MS-Agent framework (CVE-2026-2256); a PyMuPDF 1.26.5 path-traversal leading to arbitrary file write; prototype pollution in CASL Ability (rulesToFields/setByPath); an out-of-bounds read (DoS) in libheif’s uncompressed codec (CVE-2025-65586); and a code-in‑/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
a0f31412a4a4c0c564313e4c27eada7646b25494d534adc7af7e15d8f72f7e43
Enrichment time
2026-03-09T20:52:12Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.