## CVE-2022-37439

CVE-2022-37439 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. In Splunk Enterprise and Universal Forwarder versions, indexing a specially crafted ZIP file using the file monitoring input can result in a crash of the application. Attempts to restart the application would result in a crash and would require manually removing the malformed file. EPSS estimates a 0.19% chance of exploitation in the next 30 days.

## Description

In Splunk Enterprise and Universal Forwarder versions, indexing a specially crafted ZIP file using the file monitoring input can result in a crash of the application. Attempts to restart the application would result in a crash and would require manually removing the malformed file.

## Metrics

**CVSS:** 5.5/10  
**CVSS Vector:** CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H  
**EPSS Probability:** 0.19% (9.0th percentile)  
Probability of exploitation in the next 30 days. [Learn more](https://www.first.org/epss/)

## Weakness Enumeration

- [CWE-409](https://cwe.mitre.org/data/definitions/409.html)

## Affected Software

| Vendor | Product | Versions |  
| --- | --- | --- |  
| Splunk | Splunk | >= 8.1.0, < 8.1.11 |  
| Splunk | Splunk | >= 8.2.0, < 8.2.7.1 |  
| Splunk | Universal Forwarder | >= 8.1.0, < 8.1.11 |  
| Splunk | Universal Forwarder | >= 8.2.0, < 8.2.7.1 |

## References

- [Vendor Advisory](https://research.splunk.com/application/b237d393-2f57-4531-aad7-ad3c17c8b041)  
- [Vendor Advisory](https://www.splunk.com/en_us/product-security/announcements/svd-2022-0803.html)

## Timeline

**Published:** Aug 16, 2022  
**Last Modified:** Jun 17, 2026  
**Status:** Modified

## Frequently Asked Questions

**What is CVE-2022-37439?**  
In Splunk Enterprise and Universal Forwarder versions, indexing a specially crafted ZIP file using the file monitoring input can result in a crash of the application. Attempts to restart the application would result in a crash and would require manually removing the malformed file.

**How severe is CVE-2022-37439?**  
CVE-2022-37439 has a CVSS score of 5.5/10 (MEDIUM severity). The EPSS model estimates a 0.19% probability of exploitation in the next 30 days.

**How do I fix CVE-2022-37439?**  
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also [run a Strix scan](https://app.strix.ai/) to test if your systems are affected.
