CVE-2024-8088

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
22/08/2024
Last modified:
03/11/2025

Description

There is a HIGH severity vulnerability affecting the CPython "zipfile"<br /> module affecting "zipfile.Path". Note that the more common API "zipfile.ZipFile" class is unaffected.<br /> <br /> <br /> <br /> <br /> <br /> When iterating over names of entries in a zip archive (for example, methods<br /> of "zipfile.Path" like "namelist()", "iterdir()", etc)<br /> the process can be put into an infinite loop with a maliciously crafted<br /> zip archive. This defect applies when reading only metadata or extracting<br /> the contents of the zip archive. Programs that are not handling<br /> user-controlled zip archives are not affected.

References to Advisories, Solutions, and Tools