
CVE-2026-31988 yauzl (aka Yet Another Unzip Library) version 3.2.0 for Node.js contains an off-by-one error in the NTFS extended timestamp extra field parser within the getLastModDa… https://www.cve.org/CVERecord?id=CVE-2026-31988
Post summary
CVE-2026-31988 describes an off-by-one error in yauzl’s NTFS timestamp parser within Node.js. No PoC, exploit, or patch information is included.

