[javasecurity:S6096] Zip slip not reported when unzip is done using Java NIO

This answer was ment to be posted here [javasecurity:S6096] Zip slip reported when prevented using Java NIO - #4

Hi @Dave562

Thanks again for your feedback and for the code example you shared. I confirmed that I could reproduce this FP. It’s caused by a known limitation in our engine.

I can also confirm that the code you shared is not vulnerable to ZipSlip and you can safely change the issue status to Resolved (False-Positive).

Pierre-Loup