# CVE-2026-55195

## Summary

- **CVE ID:** CVE-2026-55195
- **Severity:** HIGH
- **CVSS Score:** 8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-409
- **Published:** Jul 8, 2026
- **Last Modified:** Jul 9, 2026

## Description

py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Prior to 1.1.3, py7zr's Worker.decompress() extracted archive entries without tracking total decompressed size, allowing a crafted .7z file such as a 15.6 KB archive that expands to 100 MB to exhaust disk or memory before extraction completes. This issue is fixed in version 1.1.3.

## Affected Products

- miurahr — py7zr (< 1.1.3)

## References

- [CNA](https://github.com/miurahr/py7zr/security/advisories/GHSA-gjrg-mpp7-g774)
- [CNA](https://github.com/miurahr/py7zr/commit/28faf107b64374fa5a02bfb93aa2024e281ca97b)
- [CNA](https://github.com/miurahr/py7zr/releases/tag/v1.1.3)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.32%
- **EPSS Percentile:** 24.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._