VYPR

rpm package

opensuse/python-py7zr&distro=openSUSE Leap 16.0

pkg:rpm/opensuse/python-py7zr&distro=openSUSE%20Leap%2016.0

Vulnerabilities (3)

  • CVE-2026-55206HigJul 8, 2026
    affected < 1.0.0-bp160.2.1fixed 1.0.0-bp160.2.1

    py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Prior to 1.1.3, PackInfo._read() in archiveinfo.py used an O(n^2) cumulative sum pattern for attacker-controlled numstreams values parsed from archive header

  • CVE-2026-55195HigJul 8, 2026
    affected < 1.0.0-bp160.2.1fixed 1.0.0-bp160.2.1

    py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Prior to 1.1.3, py7zr's Worker.decompress() extracted archive entries without tracking total decompressed size, allowing a crafted .7z file such as a 15.6 KB

  • CVE-2026-23879HigJun 24, 2026
    affected < 1.0.0-bp160.2.1fixed 1.0.0-bp160.2.1

    py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Versions 1.1.2 and below contain an an arbitrary file write vulnerability, which allows symbolic links to be recreated outside the destination directory via