Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-55206

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 6.5

Описание

py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Prior to 1.1.3, PackInfo._read() in archiveinfo.py used an O(n^2) cumulative sum pattern for attacker-controlled numstreams values parsed from archive headers, allowing a crafted .7z archive to cause excessive CPU consumption during SevenZipFile.init() before extraction. This issue is fixed in version 1.1.3.

A flaw was found in py7zr, a Python library for 7zip archives. A remote attacker could exploit this vulnerability by providing a specially crafted .7z archive. This archive, when processed by the SevenZipFile.init() function, triggers an inefficient algorithmic complexity (CWE-407) during header parsing. This leads to excessive CPU consumption, resulting in a Denial of Service (DoS) for any application that opens untrusted .7z archives using py7zr.

Отчет

This Moderate severity flaw in the py7zr library can lead to a Denial of Service. Applications that utilize py7zr to open or process untrusted .7z archives are vulnerable to excessive CPU consumption. This occurs due to an inefficient algorithm when parsing specially crafted archive headers, allowing a remote attacker to trigger the resource exhaustion without requiring file extraction.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-606
https://bugzilla.redhat.com/show_bug.cgi?id=2498253py7zr: py7zr: Denial of Service via crafted .7z archives due to inefficient algorithmic complexity

6.5 Medium

CVSS3

Связанные уязвимости

ubuntu
27 дней назад

py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Prior to 1.1.3, PackInfo._read() in archiveinfo.py used an O(n^2) cumulative sum pattern for attacker-controlled numstreams values parsed from archive headers, allowing a crafted .7z archive to cause excessive CPU consumption during SevenZipFile.init() before extraction. This issue is fixed in version 1.1.3.

nvd
27 дней назад

py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Prior to 1.1.3, PackInfo._read() in archiveinfo.py used an O(n^2) cumulative sum pattern for attacker-controlled numstreams values parsed from archive headers, allowing a crafted .7z archive to cause excessive CPU consumption during SevenZipFile.init() before extraction. This issue is fixed in version 1.1.3.

debian
27 дней назад

py7zr is a Python-based library and utility to support 7zip archive co ...

github
около 2 месяцев назад

py7zr: O(n^2) algorithmic complexity DoS in PackInfo._read()

suse-cvrf
около 1 месяца назад

Security update for python-py7zr

6.5 Medium

CVSS3