VYPR

rpm package

opensuse/python-py7zr&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/python-py7zr&distro=openSUSE%20Tumbleweed

Vulnerabilities (5)

  • CVE-2026-55206HigJul 8, 2026
    affected < 1.1.3-1.1fixed 1.1.3-1.1

    py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Prior to 1.1.3, PackInfo._read() in archiveinfo.py used an O(n^2) cumulative sum pattern for attacker-controlled numstreams values parsed from archive header

  • CVE-2026-55195HigJul 8, 2026
    affected < 1.1.3-1.1fixed 1.1.3-1.1

    py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Prior to 1.1.3, py7zr's Worker.decompress() extracted archive entries without tracking total decompressed size, allowing a crafted .7z file such as a 15.6 KB

  • CVE-2026-23879HigJun 24, 2026
    affected < 1.1.3-1.1fixed 1.1.3-1.1

    py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Versions 1.1.2 and below contain an an arbitrary file write vulnerability, which allows symbolic links to be recreated outside the destination directory via

  • CVE-2025-6176HigOct 31, 2025
    affected < 1.1.0-1.1fixed 1.1.0-1.1

    Scrapy versions up to 2.13.2 are vulnerable to a denial of service (DoS) attack due to a flaw in its brotli decompression implementation. The protection mechanism against decompression bombs fails to mitigate the brotli variant, allowing remote servers to crash clients with less

  • CVE-2022-44900CriDec 6, 2022
    affected < 0.20.8-2.6fixed 0.20.8-2.6

    A directory traversal vulnerability in the SevenZipFile.extractall() function of the python library py7zr v0.20.0 and earlier allows attackers to write arbitrary files via extracting a crafted 7z file.