Search CVE reports


Toggle filters

1 – 4 of 4 results


CVE-2026-55206

Medium priority
Needs evaluation

py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Prior to 1.1.3, PackInfo._read() in archiveinfo.py used an O(n^2) cumulative sum pattern for...

1 affected package

py7zr

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
py7zr Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-55195

Medium priority
Needs evaluation

py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Prior to 1.1.3, py7zr's Worker.decompress() extracted archive entries without tracking total decompressed...

1 affected package

py7zr

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
py7zr Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-23879

Medium priority
Needs evaluation

py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Versions 1.1.2 and below contain an an arbitrary file write vulnerability, which allows symbolic links to...

1 affected package

py7zr

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
py7zr Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-44900

Medium priority

Some fixes available 1 of 4

A directory traversal vulnerability in the SevenZipFile.extractall() function of the python library py7zr v0.20.0 and earlier allows attackers to write arbitrary files via extracting a crafted 7z file.

1 affected package

py7zr

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
py7zr Not affected Fixed Not in release Not in release
Show less packages