CVE-2025-8291

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
07/10/2025
Last modified:
29/10/2025

Description

The &amp;#39;zipfile&amp;#39; module would not check the validity of the ZIP64 End of<br /> Central Directory (EOCD) Locator record offset value would not be used to<br /> locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be<br /> assumed to be the previous record in the ZIP archive. This could be abused<br /> to create ZIP archives that are handled differently by the &amp;#39;zipfile&amp;#39; module<br /> compared to other ZIP implementations.<br /> <br /> <br /> Remediation maintains this behavior, but checks that the offset specified<br /> in the ZIP64 EOCD Locator record matches the expected value.