Hello ZAP maintainers,
Microsoft Defender Antivirus flags the official ZAP 2.17.0 cross-platform package at:
https://github.com/zaproxy/zaproxy/releases/download/v2.17.0/ZAP_2.17.0_Crossplatform.zip
Observed details:
- File: ZAP_2.17.0_Crossplatform.zip
- Size: 286,652,857 bytes
- Expected SHA-256 (not locally verified): 94c8f767b1c2e94f0db66b3ae56514d5e3f5a728ee1b6c798e0c8fe2d61fbff0
- Download/detection time: 2026-09-03 15:22 CST (UTC+8)
- Detection: Program:Java/Multiverze!rfn
- Threat ID: 453479
- Severity: High
- Defender engine: 1.1.26070.7
- Security intelligence: 1.457.447.0
Defender blocked access before the local SHA-256 could be completed. The archive was not restored, extracted, or executed, and no Defender exclusion or bypass was attempted.
Microsoft's standard file submission form has a 50 MB limit, so I prepared the official download URL for submission through Microsoft's URL-analysis form.
Could you please confirm:
1. Whether the exact official package and expected SHA-256 above are valid for the 2.17.0 release.
2. Whether this Defender detection is known or reproducible.
3. Whether the project can provide a credible false-positive statement or submit the exact release artifact to Microsoft for analysis.
The integration remains blocked pending Microsoft or ZAP confirmation.
Thank you.