FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Erlang/OTP -- relative path traversal in the zip module

Affected packages
erlang < 28.5.0.4,4
erlang-runtime27 < 27.3.4.15
erlang-runtime28 < 28.5.0.4
erlang-runtime29 < 29.0.4

Details

VuXML ID 445e11d4-89e1-11f1-b35c-4c526214c986
Discovery 2026-07-27
Entry 2026-07-27

The Erlang/OTP team reports:

Fixed a bug where zip:unzip/1,2 and zip:extract/1,2 were vulnerable to a relative path traversal attack. A crafted zip archive containing entry names such as ../x/y could have caused files to be written outside the intended extraction directory.

References

CVE Name CVE-2026-47078
URL https://github.com/erlang/otp/releases/tag/OTP-29.0.4