An issue was found in the CPython `zipfile` module affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior.
The zipfile module is vulnerable to “quoted-overlap” zip-bombs which exploit the zip format to create a zip-bomb with a high compression ratio. The fixed versions of CPython makes the zipfile module reject zip archives which overlap entries in the archive.
The zipfile module is vulnerable to “quoted-overlap” zip-bombs which exploit the zip format to create a zip-bomb with a high compression ratio. The fixed versions of CPython makes the zipfile module reject zip archives which overlap entries in the archive.
Subscriptions
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3771-1 | python2.7 security update |
Debian DLA |
DLA-3772-1 | python3.7 security update |
Debian DLA |
DLA-3948-1 | pypy3 security update |
Debian DLA |
DLA-3980-1 | python3.9 security update |
EUVD |
EUVD-2024-16245 | An issue was found in the CPython `zipfile` module affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior. The zipfile module is vulnerable to “quoted-overlap” zip-bombs which exploit the zip format to create a zip-bomb with a high compression ratio. The fixed versions of CPython makes the zipfile module reject zip archives which overlap entries in the archive. |
Ubuntu USN |
USN-6891-1 | Python vulnerabilities |
Ubuntu USN |
USN-7212-1 | Python 2.7 vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 03 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 11 Apr 2025 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: PSF
Published:
Updated: 2025-11-03T21:50:58.107Z
Reserved: 2024-01-11T22:16:41.964Z
Link: CVE-2024-0450
Updated: 2025-11-03T21:50:58.107Z
Status : Awaiting Analysis
Published: 2024-03-19T16:15:09.180
Modified: 2025-11-03T22:16:34.090
Link: CVE-2024-0450
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN