Improper Path Validation in Geo IP Database Extraction by Regular Labs
CVE-2026-65431

9.8CRITICAL

Key Information:

Vendor
CVE Published:
23 July 2026

What is CVE-2026-65431?

The Geo IP database update archives from Regular Labs expose a vulnerability whereby files are extracted without adequate path validation. This flaw permits unauthorized files or malicious payloads to be written to improper locations, potentially compromising the integrity of the system and creating avenues for further exploitation. Users of this product should take caution and ensure appropriate measures are implemented to mitigate any risks associated with unsafe file extractions.

Affected Version(s)

GeoIP extension for Joomla 1.0.0-6.3.8

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.