High severityGHSA Advisory· Published Jul 8, 2026· Updated Jul 10, 2026
CVE-2026-55206
CVE-2026-55206
Description
py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Prior to 1.1.3, PackInfo._read() in archiveinfo.py used an O(n^2) cumulative sum pattern for attacker-controlled numstreams values parsed from archive headers, allowing a crafted .7z archive to cause excessive CPU consumption during SevenZipFile.init() before extraction. This issue is fixed in version 1.1.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
py7zrPyPI | < 1.1.3 | 1.1.3 |
Affected products
3- osv-coords2 versionspkg:rpm/opensuse/python-py7zr&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/python-py7zr&distro=openSUSE%20Tumbleweed
< 1.0.0-bp160.2.1+ 1 more
- (no CPE)range: < 1.0.0-bp160.2.1
- (no CPE)range: < 1.1.3-1.1
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.