CVE-2019-9674
published 2020-02-04CVE-2019-9674: Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb.
PriorityP336high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
5.54%
92.0th percentile
Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | python2.7 | — | — |
| msrc | cbl2_python2_2.7.18-8_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_python2_2.7.18-5_on_cbl_mariner_1.0 | — | — |
| python | python | 3.2 – 3.8 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.6HIGH
vendor_ubuntu7.6HIGH
vendor_debian7.5LOW
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
python2.7 vulnerabilities
osv·2025-01-16·CVSS 7.5
CVE-2019-9674 [HIGH] python2.7 vulnerabilities
python2.7 vulnerabilities
It was discovered that Python incorrectly handled certain ZIP files. An
attacker could possibly use this issue to cause a denial of service. This
issue only affected Ubuntu 22.04 LTS. (CVE-2019-9674)
It was discovered that Python incorrectly handled certain inputs. If a
user or an automated system were tricked into running a specially
crafted input, a remote attacker could possibly use this issue to cause a
denial of service. (CVE-2022-45061)
It was discovered that Python incorrectly handled certain crafted ZIP
files. An attacker could possibly use this issue to crash the program,
resulting in a denial of service. (CVE-2024-0450)
OSV
python3.5, python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12 vulnerabilities
osv·2024-07-11·CVSS 7.6
CVE-2015-20107 [HIGH] python3.5, python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12 vulnerabilities
python3.5, python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12 vulnerabilities
It was discovered that Python incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 14.04 LTS and Ubuntu 18.04 LTS.
(CVE-2015-20107)
It was discovered that Python incorrectly used regular expressions
vulnerable to catastrophic backtracking. A remote attacker could possibly
use this issue to cause a denial of service. This issue only affected
Ubuntu 14.04 LTS. (CVE-2018-1060, CVE-2018-1061)
It was discovered that Python failed to initialize Expat’s hash salt. A
remote attacker could possibly use this issue to cause hash collisions,
leading to a denial of service. This issue only affected Ubuntu 14.04 L
GHSA
Fides Webserver Vulnerable to Zip Bomb File Uploads
ghsa·2023-07-18
CVE-2023-37480 [LOW] CWE-400 Fides Webserver Vulnerable to Zip Bomb File Uploads
Fides Webserver Vulnerable to Zip Bomb File Uploads
### Impact
The Fides webserver is vulnerable to a type of Denial of Service (DoS) attack. Attackers can exploit a weakness in the connector template upload feature to upload a malicious zip bomb file, resulting in resource exhaustion and service unavailability for all users of the Fides webserver.
This vulnerability affects Fides versions `2.11.0` through `2.15.1`. Exploitation is limited to users with elevated privileges with the `CONNECTOR_TEMPLATE_REGISTER` scope, which includes root users and users with the owner role.
### Patches
The vulnerability has been patched in Fides version `2.16.0`. Users are advised to upgrade to this version or later to secure their systems against this threat.
### Workarounds
There is no known workarou
OSV
Fides Webserver Vulnerable to Zip Bomb File Uploads
osv·2023-07-18
CVE-2023-37480 [LOW] Fides Webserver Vulnerable to Zip Bomb File Uploads
Fides Webserver Vulnerable to Zip Bomb File Uploads
### Impact
The Fides webserver is vulnerable to a type of Denial of Service (DoS) attack. Attackers can exploit a weakness in the connector template upload feature to upload a malicious zip bomb file, resulting in resource exhaustion and service unavailability for all users of the Fides webserver.
This vulnerability affects Fides versions `2.11.0` through `2.15.1`. Exploitation is limited to users with elevated privileges with the `CONNECTOR_TEMPLATE_REGISTER` scope, which includes root users and users with the owner role.
### Patches
The vulnerability has been patched in Fides version `2.16.0`. Users are advised to upgrade to this version or later to secure their systems against this threat.
### Workarounds
There is no known workarou
GHSA
GHSA-h33x-58qw-vqrp: Lib/zipfile
ghsa_unreviewed·2022-05-24
CVE-2019-9674 [HIGH] CWE-400 GHSA-h33x-58qw-vqrp: Lib/zipfile
Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb.
OSV
python2.7, python3.7, python3.8 vulnerabilities
osv·2021-03-12·CVSS 7.5
CVE-2019-9674 [HIGH] python2.7, python3.7, python3.8 vulnerabilities
python2.7, python3.7, python3.8 vulnerabilities
USN-4754-1 fixed vulnerabilities in Python. This update provides
the corresponding updates for Ubuntu 18.04 and Ubuntu 20.04.
In the case of Python 2.7 for 20.04, these additional fixes are included:
It was dicovered that Python allowed remote attackers to cause a denial of
service (resource consumption) via a ZIP bomb. (CVE-2019-9674)
It was discovered that Python had potentially misleading information about
whether sorting occurs. This fix updates the documentation about it.
(CVE-2019-17514)
It was discovered that Python incorrectly handled certain TAR archives.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2019-20907)
It was discovered that Python allowed an HTTP server to conduct Regular
Expression Den
OSV
python2.7, python3.4, python3.5, python3.6, python3.8 vulnerabilities
osv·2020-07-22·CVSS 7.5
CVE-2019-17514 [HIGH] python2.7, python3.4, python3.5, python3.6, python3.8 vulnerabilities
python2.7, python3.4, python3.5, python3.6, python3.8 vulnerabilities
It was discovered that Python documentation had a misleading information.
A security issue could be possibly caused by wrong assumptions of this information.
This issue only affected Ubuntu 12.04 ESM, Ubuntu 14.04 ESM, Ubuntu 16.04 LTS and
Ubuntu 18.04 LTS. (CVE-2019-17514)
It was discovered that Python incorrectly handled certain TAR archives.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2019-20907)
It was discovered that incorrectly handled certain ZIP files. An attacker
could possibly use this issue to cause a denial of service. This issue only
affected Ubuntu 12.04 ESM, Ubuntu 14.04 ESM, Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
(CVE-2019-9674)
It was discovered that Python incorrectl
OSV
CVE-2019-9674: Lib/zipfile
osv·2020-02-04·CVSS 7.5
CVE-2019-9674 [HIGH] CVE-2019-9674: Lib/zipfile
Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb.
Ubuntu
Python 2.7 vulnerabilities
vendor_ubuntu·2025-01-16·CVSS 7.5
CVE-2022-45061 [HIGH] Python 2.7 vulnerabilities
Title: Python 2.7 vulnerabilities
Summary: Several security issues were fixed in Python 2.7.
It was discovered that Python incorrectly handled certain ZIP files. An
attacker could possibly use this issue to cause a denial of service. This
issue only affected Ubuntu 22.04 LTS. (CVE-2019-9674)
It was discovered that Python incorrectly handled certain inputs. If a
user or an automated system were tricked into running a specially
crafted input, a remote attacker could possibly use this issue to cause a
denial of service. (CVE-2022-45061)
It was discovered that Python incorrectly handled certain crafted ZIP
files. An attacker could possibly use this issue to crash the program,
resulting in a denial of service. (CVE-2024-0450)
Instructions: In general, a standard system update will make all
Ubuntu
Python vulnerabilities
vendor_ubuntu·2024-07-11·CVSS 7.6
CVE-2021-29921 [HIGH] Python vulnerabilities
Title: Python vulnerabilities
Summary: Several security issues were fixed in Python.
It was discovered that Python incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 14.04 LTS and Ubuntu 18.04 LTS.
(CVE-2015-20107)
It was discovered that Python incorrectly used regular expressions
vulnerable to catastrophic backtracking. A remote attacker could possibly
use this issue to cause a denial of service. This issue only affected
Ubuntu 14.04 LTS. (CVE-2018-1060, CVE-2018-1061)
It was discovered that Python failed to initialize Expat’s hash salt. A
remote attacker could possibly use this issue to cause hash collisions,
leading to a denial of service. This issue only affected Ubuntu 14.04 LTS.
(CVE-2018-14647)
Ubuntu
Python vulnerabilities
vendor_ubuntu·2021-03-12·CVSS 7.5
CVE-2020-8492 [HIGH] Python vulnerabilities
Title: Python vulnerabilities
Summary: Several security issues were fixed in Python 2.7 and Python 3.8.
USN-4754-1 fixed vulnerabilities in Python. This update provides
the corresponding updates for Ubuntu 18.04 and Ubuntu 20.04.
In the case of Python 2.7 for 20.04, these additional fixes are included:
It was dicovered that Python allowed remote attackers to cause a denial of
service (resource consumption) via a ZIP bomb. (CVE-2019-9674)
It was discovered that Python had potentially misleading information about
whether sorting occurs. This fix updates the documentation about it.
(CVE-2019-17514)
It was discovered that Python incorrectly handled certain TAR archives.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2019-20907)
It was discovered that Python
Ubuntu
Python vulnerabilities
vendor_ubuntu·2020-07-22·CVSS 7.5
CVE-2019-20907 [HIGH] Python vulnerabilities
Title: Python vulnerabilities
Summary: Several security issues were fixed in Python.
It was discovered that Python documentation had a misleading information.
A security issue could be possibly caused by wrong assumptions of this information.
This issue only affected Ubuntu 12.04 ESM, Ubuntu 14.04 ESM, Ubuntu 16.04 LTS and
Ubuntu 18.04 LTS. (CVE-2019-17514)
It was discovered that Python incorrectly handled certain TAR archives.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2019-20907)
It was discovered that incorrectly handled certain ZIP files. An attacker
could possibly use this issue to cause a denial of service. This issue only
affected Ubuntu 12.04 ESM, Ubuntu 14.04 ESM, Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
(CVE-2019-9674)
It was discovered that P
Microsoft
Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb.
vendor_msrc·2020-02-11·CVSS 7.5
CVE-2019-9674 [HIGH] CWE-400 Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb.
Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Customer Action
Red Hat
python: Nested zip file (Zip bomb) vulnerability in Lib/zipfile.py
vendor_redhat·2019-03-11·CVSS 7.5
CVE-2019-9674 [HIGH] CWE-409 python: Nested zip file (Zip bomb) vulnerability in Lib/zipfile.py
python: Nested zip file (Zip bomb) vulnerability in Lib/zipfile.py
Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb.
A ZIP bomb attack was found in the Python zipfile module. A remote attacker could abuse this flaw by providing a specially crafted ZIP file that, when decompressed by zipfile, would exhaust system resources resulting in a denial of service.
Statement: There is no plan to fix this flaw. Programs using the Python zipfile module should be responsible for validating external untrusted ZIP files. For further details, please refer to the following URLs:
[1] https://docs.python.org/dev/library/zipfile.html#decompression-pitfalls
[2] https://python-security.readthedocs.io/security.html#archives-and-z
Debian
CVE-2019-9674: python2.7 - Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial...
vendor_debian·2019·CVSS 7.5
CVE-2019-9674 [HIGH] CVE-2019-9674: python2.7 - Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial...
Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb.
Scope: local
bullseye: open
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-9674 python3: python: Nested zip file (Zip bomb) vulnerability in Lib/zipfile.py [fedora-all]
bugzilla·2020-02-07·CVSS 7.5
CVE-2019-9674 [HIGH] CVE-2019-9674 python3: python: Nested zip file (Zip bomb) vulnerability in Lib/zipfile.py [fedora-all]
CVE-2019-9674 python3: python: Nested zip file (Zip bomb) vulnerability in Lib/zipfile.py [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mu
Bugzilla
CVE-2019-9674 python: Nested zip file (Zip bomb) vulnerability in Lib/zipfile.py
bugzilla·2020-02-07·CVSS 7.5
CVE-2019-9674 [HIGH] CVE-2019-9674 python: Nested zip file (Zip bomb) vulnerability in Lib/zipfile.py
CVE-2019-9674 python: Nested zip file (Zip bomb) vulnerability in Lib/zipfile.py
Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb.
References:
https://bugs.python.org/issue36260
https://bugs.python.org/issue36462
https://github.com/python/cpython/blob/master/Lib/zipfile.py
https://python-security.readthedocs.io/security.html#archives-and-zip-bomb
Discussion:
Created python3 tracking bugs for this issue:
Affects: fedora-all [bug 1800750]
---
> through 3.7.2
Where is this information coming from?
Also, upstream Python seem to have resolved this via documentation update. At least that's what the two bugs links suggest.
---
There is new fix for this issue, only the documentation has been updated to wa
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-05/msg00041.htmlhttps://bugs.python.org/issue36260https://bugs.python.org/issue36462https://github.com/python/cpython/blob/master/Lib/zipfile.pyhttps://python-security.readthedocs.io/security.html#archives-and-zip-bombhttps://security.netapp.com/advisory/ntap-20200221-0003/https://usn.ubuntu.com/4428-1/https://www.python.org/news/security/http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-05/msg00041.htmlhttps://bugs.python.org/issue36260https://bugs.python.org/issue36462https://github.com/python/cpython/blob/master/Lib/zipfile.pyhttps://python-security.readthedocs.io/security.html#archives-and-zip-bombhttps://security.netapp.com/advisory/ntap-20200221-0003/https://usn.ubuntu.com/4428-1/https://www.python.org/news/security/
2020-02-04
Published