Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

7-Zip — Vulnerabilities & Security Advisories 21

All 21 CVE vulnerabilities found in 7-Zip, with AI-generated Chinese analysis, references, and POCs.

This page catalogs Common Weakness Enumerations associated with 7-Zip, a popular file archiver developed by Igor Pavlov. It aggregates security data to help researchers and administrators understand the historical and current security posture of this widely used utility. The content collected spans a broad timeline, including vulnerabilities from early releases through recent updates, ensuring that both legacy and modern deployment scenarios are addressed. Users can track vendor advisories issued by Igor Pavlov and the official 7-Zip team to stay informed about patched issues. The page allows visitors to understand specific weakness classes that have affected the software, such as buffer overflows, path traversal, or improper input validation, by providing context on how these flaws manifest within the application's codebase. Furthermore, users can look up a product's vulnerability history to assess risk exposure over time, identifying trends in defect introduction and resolution. This resource serves as a centralized reference for security analysts evaluating the integrity of 7-Zip installations within enterprise or personal environments. By reviewing the aggregated data, one can better comprehend the nature of past security incidents and apply appropriate mitigations. The information presented is strictly factual, focusing on technical details without promotional language, to facilitate accurate risk assessment and informed decision-making regarding software updates and configuration hardening.

Vendor: 7-Zip

CVE IDTitleCVSSSeverityPublished
CVE-2026-14266 7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability CWE-122--2026-07-29
CVE-2026-58052 7-Zip - Mark-of-the-Web Bypass via RAR5 Alternate Data Stream Name Collision CWE-693 3.3 Low2026-06-28
CVE-2026-48112 GHSL-2026-122 7-Zip Ar SYMDEF OOB Read CWE-190 6.5 Medium2026-06-05
CVE-2026-48111 GHSL-2026-121 7-Zip UEFI DEPEX OOB Read CWE-125 4.3 Medium2026-06-05
CVE-2026-48104 GHSL-2026-120: 7-Zip SquashFS BlockToNode uninitialized heap read CWE-908 4.2 Medium2026-06-05
CVE-2026-48103 GHSL-2026-119 7-Zip WIM SecurityId OOB read CWE-125 4.3 Medium2026-06-05
CVE-2026-48102 GHSL-2026-118: 7-Zip UDF Field OOB Read CWE-125 3.1 Low2026-06-05
CVE-2026-48101 GHSL-2026-117: 7-Zip UEFI Capsule uninitialized heap memory disclosure CWE-908 6.5 Medium2026-06-05
CVE-2026-48095 GHSL-2026-140_7-Zip: 7-Zip has a heap buffer overflow via NTFS compressed stream buffer under-allocation CWE-787 8.8 High2026-06-05
CVE-2026-48092 7-Zip SquashFS Fragment Offset Overflow (GHSL-2026-116) CWE-125 4.3 Medium2026-06-05
CVE-2025-11002 7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability CWE-22 8.8 -2026-01-23
CVE-2025-11001 7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability CWE-22 8.8AIHighAI2025-11-19
CVE-2025-55188 7-Zip 安全漏洞 CWE-59 3.6 Low2025-08-08
CVE-2025-53817 GHSL-2025-059 - 7-Zip - Null pointer array write attempt in NArchive::NCom::CHandler::GetStream CWE-476 6.2AIMediumAI2025-07-17
CVE-2025-53816 GHSL-2025-058 - 7-Zip Multi-byte write heap buffer overflow in NCompress::NRar5::CDecoder CWE-122 6.2AIMediumAI2025-07-17
CVE-2022-47111 编号已被CVE保留 CWE-754 2.5 Low2025-04-19
CVE-2022-47112 编号已被CVE保留 CWE-754 2.5 Low2025-04-19
CVE-2025-0411 7-Zip Mark-of-the-Web Bypass Vulnerability CWE-693 7.8 -2025-01-25
CVE-2024-11477 7-Zip Zstandard Decompression Integer Underflow Remote Code Execution Vulnerability CWE-191 9.8 -2024-11-22
CVE-2024-11612 7-Zip CopyCoder Infinite Loop Denial-of-Service Vulnerability CWE-835 7.5 -2024-11-22
CVE-2023-40481 7-Zip SquashFS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability CWE-787 7.8 -2024-05-03

All 21 known CVE vulnerabilities affecting 7-Zip with full Chinese analysis, references, and POCs where available.