High severityGHSA Advisory· Published Jul 8, 2026· Updated Jul 10, 2026
CVE-2026-55195
CVE-2026-55195
Description
py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Prior to 1.1.3, py7zr's Worker.decompress() extracted archive entries without tracking total decompressed size, allowing a crafted .7z file such as a 15.6 KB archive that expands to 100 MB to exhaust disk or memory before extraction completes. This issue is fixed in version 1.1.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
py7zrPyPI | < 1.1.3 | 1.1.3 |
Affected products
3- osv-coords2 versionspkg:rpm/opensuse/python-py7zr&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/python-py7zr&distro=openSUSE%20Tumbleweed
< 1.0.0-bp160.2.1+ 1 more
- (no CPE)range: < 1.0.0-bp160.2.1
- (no CPE)range: < 1.1.3-1.1
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.