<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 14:06:34 +0000</lastBuildDate>
    <item>
      <title>BREW-aqtinstall-CVE-2026-55206 — py7zr: O(n^2) algorithmic complexity DoS in PackInfo._read()</title>
      <link>https://cve.radiocsirt.org/vuln/brew-aqtinstall-cve-2026-55206</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: aqtinstall&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;PackInfo._read() uses an O(n^2) cumulative sum pattern where
  numstreams is read directly from the archive header. A crafted .7z
  archive with a large numstreams value causes excessive CPU consumption
   during SevenZipFile.__init__() — no extraction is needed. A 50 KB
  archive takes ~7 seconds of CPU time.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The vulnerable code is in PackInfo._read() (archiveinfo.py):&lt;/p&gt;
&lt;p&gt;self.packpositions = [sum(self.packsizes[:i]) for i in
  range(self.numstreams + 1)]&lt;/p&gt;
&lt;p&gt;numstreams is parsed from the archive header via read_uint64() and is
  attacker-controlled. Each sum(self.packsizes[:i]) re-sums from the
  beginning, producing O(n^2) total work. This runs during header
  parsing in SevenZipFile.__init__(), before any extraction.&lt;/p&gt;
&lt;p&gt;Suggested fix — replace with O(n) cumulative sum:&lt;/p&gt;
&lt;p&gt;from itertools import accumulate
  self.packpositions = [0] + list(accumulate(self.packsizes))
### PoC
``` import struct, io, binascii, time
  import py7zr
  from py7zr.archiveinfo import write_uint64, PROPERTY&lt;/p&gt;
&lt;p&gt;MAGIC = b&amp;#39;\x37\x7a\xbc\xaf\x27\x1c&amp;#39;&lt;/p&gt;
&lt;p&gt;def encode_uint64(v):
      buf = io.BytesIO()
      write_uint64(buf, v)
      return buf.getvalue()&lt;/p&gt;
&lt;p&gt;def build_7z_with_streams(numstreams):
      header = io.BytesIO()
      header.write(PROPERTY.HEADER)
      header.write(PROPERTY.MAIN_STREAMS_INFO)
      header.write(PROPERTY.PACK_INFO)
      header.write(encode_uint64(0))
      header.write(encode_uint64(numstreams))
      header.write(PROPERTY.SIZE)
      for _ in range…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: aqtinstall&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;PackInfo._read() uses an O(n^2) cumulative sum pattern where
  numstreams is read directly from the archive header. A crafted .7z
  archive with a large numstreams value causes excessive CPU consumption
   during SevenZipFile.__init__() — no extraction is needed. A 50 KB
  archive takes ~7 seconds of CPU time.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The vulnerable code is in PackInfo._read() (archiveinfo.py):&lt;/p&gt;
&lt;p&gt;self.packpositions = [sum(self.packsizes[:i]) for i in
  range(self.numstreams + 1)]&lt;/p&gt;
&lt;p&gt;numstreams is parsed from the archive header via read_uint64() and is
  attacker-controlled. Each sum(self.packsizes[:i]) re-sums from the
  beginning, producing O(n^2) total work. This runs during header
  parsing in SevenZipFile.__init__(), before any extraction.&lt;/p&gt;
&lt;p&gt;Suggested fix — replace with O(n) cumulative sum:&lt;/p&gt;
&lt;p&gt;from itertools import accumulate
  self.packpositions = [0] + list(accumulate(self.packsizes))
### PoC
``` import struct, io, binascii, time
  import py7zr
  from py7zr.archiveinfo import write_uint64, PROPERTY&lt;/p&gt;
&lt;p&gt;MAGIC = b&amp;#39;\x37\x7a\xbc\xaf\x27\x1c&amp;#39;&lt;/p&gt;
&lt;p&gt;def encode_uint64(v):
      buf = io.BytesIO()
      write_uint64(buf, v)
      return buf.getvalue()&lt;/p&gt;
&lt;p&gt;def build_7z_with_streams(numstreams):
      header = io.BytesIO()
      header.write(PROPERTY.HEADER)
      header.write(PROPERTY.MAIN_STREAMS_INFO)
      header.write(PROPERTY.PACK_INFO)
      header.write(encode_uint64(0))
      header.write(encode_uint64(numstreams))
      header.write(PROPERTY.SIZE)
      for _ in range…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-aqtinstall-cve-2026-55206</guid>
    </item>
    <item>
      <title>EUVD-2026-335334</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-335334</link>
      <description>EUVD-2026-335334</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-335334</guid>
    </item>
    <item>
      <title>fkie_cve-2026-55206</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55206</link>
      <description>&lt;p&gt;py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Prior to 1.1.3, PackInfo._read() in archiveinfo.py used an O(n^2) cumulative sum pattern for attacker-controlled numstreams values parsed from archive headers, allowing a crafted .7z archive to cause excessive CPU consumption during SevenZipFile.init() before extraction. This issue is fixed in version 1.1.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Prior to 1.1.3, PackInfo._read() in archiveinfo.py used an O(n^2) cumulative sum pattern for attacker-controlled numstreams values parsed from archive headers, allowing a crafted .7z archive to cause excessive CPU consumption during SevenZipFile.init() before extraction. This issue is fixed in version 1.1.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-55206</guid>
    </item>
    <item>
      <title>GHSA-h4gh-22qq-72r7 — py7zr: O(n^2) algorithmic complexity DoS in PackInfo._read()</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-h4gh-22qq-72r7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: py7zr&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;PackInfo._read() uses an O(n^2) cumulative sum pattern where
  numstreams is read directly from the archive header. A crafted .7z
  archive with a large numstreams value causes excessive CPU consumption
   during SevenZipFile.__init__() — no extraction is needed. A 50 KB
  archive takes ~7 seconds of CPU time.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The vulnerable code is in PackInfo._read() (archiveinfo.py):&lt;/p&gt;
&lt;p&gt;self.packpositions = [sum(self.packsizes[:i]) for i in
  range(self.numstreams + 1)]&lt;/p&gt;
&lt;p&gt;numstreams is parsed from the archive header via read_uint64() and is
  attacker-controlled. Each sum(self.packsizes[:i]) re-sums from the
  beginning, producing O(n^2) total work. This runs during header
  parsing in SevenZipFile.__init__(), before any extraction.&lt;/p&gt;
&lt;p&gt;Suggested fix — replace with O(n) cumulative sum:&lt;/p&gt;
&lt;p&gt;from itertools import accumulate
  self.packpositions = [0] + list(accumulate(self.packsizes))
### PoC
``` import struct, io, binascii, time
  import py7zr
  from py7zr.archiveinfo import write_uint64, PROPERTY&lt;/p&gt;
&lt;p&gt;MAGIC = b&amp;#39;\x37\x7a\xbc\xaf\x27\x1c&amp;#39;&lt;/p&gt;
&lt;p&gt;def encode_uint64(v):
      buf = io.BytesIO()
      write_uint64(buf, v)
      return buf.getvalue()&lt;/p&gt;
&lt;p&gt;def build_7z_with_streams(numstreams):
      header = io.BytesIO()
      header.write(PROPERTY.HEADER)
      header.write(PROPERTY.MAIN_STREAMS_INFO)
      header.write(PROPERTY.PACK_INFO)
      header.write(encode_uint64(0))
      header.write(encode_uint64(numstreams))
      header.write(PROPERTY.SIZE)
      for _ in range…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: py7zr&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;PackInfo._read() uses an O(n^2) cumulative sum pattern where
  numstreams is read directly from the archive header. A crafted .7z
  archive with a large numstreams value causes excessive CPU consumption
   during SevenZipFile.__init__() — no extraction is needed. A 50 KB
  archive takes ~7 seconds of CPU time.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The vulnerable code is in PackInfo._read() (archiveinfo.py):&lt;/p&gt;
&lt;p&gt;self.packpositions = [sum(self.packsizes[:i]) for i in
  range(self.numstreams + 1)]&lt;/p&gt;
&lt;p&gt;numstreams is parsed from the archive header via read_uint64() and is
  attacker-controlled. Each sum(self.packsizes[:i]) re-sums from the
  beginning, producing O(n^2) total work. This runs during header
  parsing in SevenZipFile.__init__(), before any extraction.&lt;/p&gt;
&lt;p&gt;Suggested fix — replace with O(n) cumulative sum:&lt;/p&gt;
&lt;p&gt;from itertools import accumulate
  self.packpositions = [0] + list(accumulate(self.packsizes))
### PoC
``` import struct, io, binascii, time
  import py7zr
  from py7zr.archiveinfo import write_uint64, PROPERTY&lt;/p&gt;
&lt;p&gt;MAGIC = b&amp;#39;\x37\x7a\xbc\xaf\x27\x1c&amp;#39;&lt;/p&gt;
&lt;p&gt;def encode_uint64(v):
      buf = io.BytesIO()
      write_uint64(buf, v)
      return buf.getvalue()&lt;/p&gt;
&lt;p&gt;def build_7z_with_streams(numstreams):
      header = io.BytesIO()
      header.write(PROPERTY.HEADER)
      header.write(PROPERTY.MAIN_STREAMS_INFO)
      header.write(PROPERTY.PACK_INFO)
      header.write(encode_uint64(0))
      header.write(encode_uint64(numstreams))
      header.write(PROPERTY.SIZE)
      for _ in range…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-h4gh-22qq-72r7</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11112-1 — python311-py7zr-1.1.3-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11112-1</link>
      <description>&lt;p&gt;python311-py7zr-1.1.3-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python311-py7zr-1.1.3-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11112-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-2973 — py7zr: O(n^2) algorithmic complexity DoS in PackInfo._read()</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2973</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: py7zr&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;PackInfo._read() uses an O(n^2) cumulative sum pattern where
  numstreams is read directly from the archive header. A crafted .7z
  archive with a large numstreams value causes excessive CPU consumption
   during SevenZipFile.__init__() — no extraction is needed. A 50 KB
  archive takes ~7 seconds of CPU time.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The vulnerable code is in PackInfo._read() (archiveinfo.py):&lt;/p&gt;
&lt;p&gt;self.packpositions = [sum(self.packsizes[:i]) for i in
  range(self.numstreams + 1)]&lt;/p&gt;
&lt;p&gt;numstreams is parsed from the archive header via read_uint64() and is
  attacker-controlled. Each sum(self.packsizes[:i]) re-sums from the
  beginning, producing O(n^2) total work. This runs during header
  parsing in SevenZipFile.__init__(), before any extraction.&lt;/p&gt;
&lt;p&gt;Suggested fix — replace with O(n) cumulative sum:&lt;/p&gt;
&lt;p&gt;from itertools import accumulate
  self.packpositions = [0] + list(accumulate(self.packsizes))
### PoC
``` import struct, io, binascii, time
  import py7zr
  from py7zr.archiveinfo import write_uint64, PROPERTY&lt;/p&gt;
&lt;p&gt;MAGIC = b&amp;#39;\x37\x7a\xbc\xaf\x27\x1c&amp;#39;&lt;/p&gt;
&lt;p&gt;def encode_uint64(v):
      buf = io.BytesIO()
      write_uint64(buf, v)
      return buf.getvalue()&lt;/p&gt;
&lt;p&gt;def build_7z_with_streams(numstreams):
      header = io.BytesIO()
      header.write(PROPERTY.HEADER)
      header.write(PROPERTY.MAIN_STREAMS_INFO)
      header.write(PROPERTY.PACK_INFO)
      header.write(encode_uint64(0))
      header.write(encode_uint64(numstreams))
      header.write(PROPERTY.SIZE)
      for _ in range…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: py7zr&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;PackInfo._read() uses an O(n^2) cumulative sum pattern where
  numstreams is read directly from the archive header. A crafted .7z
  archive with a large numstreams value causes excessive CPU consumption
   during SevenZipFile.__init__() — no extraction is needed. A 50 KB
  archive takes ~7 seconds of CPU time.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The vulnerable code is in PackInfo._read() (archiveinfo.py):&lt;/p&gt;
&lt;p&gt;self.packpositions = [sum(self.packsizes[:i]) for i in
  range(self.numstreams + 1)]&lt;/p&gt;
&lt;p&gt;numstreams is parsed from the archive header via read_uint64() and is
  attacker-controlled. Each sum(self.packsizes[:i]) re-sums from the
  beginning, producing O(n^2) total work. This runs during header
  parsing in SevenZipFile.__init__(), before any extraction.&lt;/p&gt;
&lt;p&gt;Suggested fix — replace with O(n) cumulative sum:&lt;/p&gt;
&lt;p&gt;from itertools import accumulate
  self.packpositions = [0] + list(accumulate(self.packsizes))
### PoC
``` import struct, io, binascii, time
  import py7zr
  from py7zr.archiveinfo import write_uint64, PROPERTY&lt;/p&gt;
&lt;p&gt;MAGIC = b&amp;#39;\x37\x7a\xbc\xaf\x27\x1c&amp;#39;&lt;/p&gt;
&lt;p&gt;def encode_uint64(v):
      buf = io.BytesIO()
      write_uint64(buf, v)
      return buf.getvalue()&lt;/p&gt;
&lt;p&gt;def build_7z_with_streams(numstreams):
      header = io.BytesIO()
      header.write(PROPERTY.HEADER)
      header.write(PROPERTY.MAIN_STREAMS_INFO)
      header.write(PROPERTY.PACK_INFO)
      header.write(encode_uint64(0))
      header.write(encode_uint64(numstreams))
      header.write(PROPERTY.SIZE)
      for _ in range…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2973</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-55206</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-55206</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: py7zr, Ubuntu:24.04:LTS: py7zr, Ubuntu:25.10: py7zr, Ubuntu:26.04:LTS: py7zr&lt;/p&gt;
&lt;p&gt;py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Prior to 1.1.3, PackInfo._read() in archiveinfo.py used an O(n^2) cumulative sum pattern for attacker-controlled numstreams values parsed from archive headers, allowing a crafted .7z archive to cause excessive CPU consumption during SevenZipFile.init() before extraction. This issue is fixed in version 1.1.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: py7zr, Ubuntu:24.04:LTS: py7zr, Ubuntu:25.10: py7zr, Ubuntu:26.04:LTS: py7zr&lt;/p&gt;
&lt;p&gt;py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Prior to 1.1.3, PackInfo._read() in archiveinfo.py used an O(n^2) cumulative sum pattern for attacker-controlled numstreams values parsed from archive headers, allowing a crafted .7z archive to cause excessive CPU consumption during SevenZipFile.init() before extraction. This issue is fixed in version 1.1.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-55206</guid>
    </item>
  </channel>
</rss>
