{"id":"CVE-2018-12418","aliases":["GHSA-5xqr-grq4-qwgx"],"url":"https://o3.security/vulnerability/CVE-2018-12418","summary":"Junrar vulnerable to Infinite Loop","details":"Archive.java in Junrar before 1.0.1, as used in Apache Tika and other products, is affected by a denial of service vulnerability due to an infinite loop when handling corrupt RAR files.","published":"2018-06-14T16:29:00.287Z","modified":"2026-07-08T14:14:16.770045Z","cvss":{"score":5.5,"severity":"MEDIUM","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"com.github.junrar:junrar","fixedVersion":"1.0.1"}],"fix":{"url":"https://github.com/junrar/junrar/commit/ad8d0ba8e155630da8a1215cee3f253e0af45817","label":"junrar/junrar@ad8d0ba"},"references":[{"type":"ADVISORY","url":"https://github.com/junrar/junrar/pull/8"},{"type":"FIX","url":"https://github.com/junrar/junrar/commit/ad8d0ba8e155630da8a1215cee3f253e0af45817"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T14:14:16.770045Z"}}