VDB
Sign up
CRITICAL9.8

PYSEC-2026-501

pyminizip affected by zlib's integer overflow/heap based buffer overflow vulnerability due to vulnerable dependency

Details

MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product.

pyminizip uses version 1.2.11 of zlib's code.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/pyminizip
Introduced in: 0

No fixed version published yet for pyminizip (pip). Pin to a known-safe version or switch to an alternative.

References