The zipfile module is vulnerable to “quoted-overlap” zip-bombs which exploit the zip format to create a zip-bomb with a high compression ratio. The fixed versions of CPython makes the zipfile module reject zip archives which overlap entries in the archive.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3771-1 | python2.7 security update |
Debian DLA |
DLA-3772-1 | python3.7 security update |
Debian DLA |
DLA-3948-1 | pypy3 security update |
Debian DLA |
DLA-3980-1 | python3.9 security update |
EUVD |
EUVD-2024-16245 | An issue was found in the CPython `zipfile` module affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior. The zipfile module is vulnerable to “quoted-overlap” zip-bombs which exploit the zip format to create a zip-bomb with a high compression ratio. The fixed versions of CPython makes the zipfile module reject zip archives which overlap entries in the archive. |
Ubuntu USN |
USN-6891-1 | Python vulnerabilities |
Ubuntu USN |
USN-7212-1 | Python 2.7 vulnerabilities |
Mon, 03 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 11 Apr 2025 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: PSF
Published:
Updated: 2025-11-03T21:50:58.107Z
Reserved: 2024-01-11T22:16:41.964Z
Link: CVE-2024-0450
Updated: 2025-11-03T21:50:58.107Z
Status : Deferred
Published: 2024-03-19T16:15:09.180
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-0450
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN