Skip to main content
Version: v1.2.x

CVE-2026-16517

CVE Details

Visit the official vulnerability details page for CVE-2026-16517 to learn more.

Initial Publication

07/21/2026

Last Update

07/22/2026

Third Party Dependency

libarchive

NIST CVE Summary

A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addition of the encryption overhead to the entry size overflows int64_t, resulting in undefined behavior. This could lead to incorrect Zip64 extension decisions or potential memory corruption.

CVE Severity

2.9

Our Official Summary

Investigation is ongoing to determine how this vulnerability affects our products.

Status

Awaiting Analysis

Affected Products & Versions

VersionPaletteAIPaletteAI VerteX
1.2.0⚠️ Impacted⚠️ Impacted

Revision History

No revisions available.