GitHub Security Lab disclosed multiple vulnerabilities affecting 7-Zip 26.00 and earlier and a separate path traversal flaw in the 7zDec sample extractor from the LZMA SDK. The issues span several archive handlers, including SquashFS, UEFI capsule and firmware parsing, UDF, WIM, and Ar, and include out-of-bounds reads, uninitialized memory disclosure, integer overflow, and denial-of-service conditions. One SquashFS flaw affects only 32-bit builds, while several of the bugs reportedly impact versions dating back to the 7-Zip 9.x line.
A fixed release, 7-Zip 26.01, was published on SourceForge after private reporting by GitHub Security Lab researcher Jaroslav Lobačevski. The coordinated disclosure maps the findings to GHSL-2026-115 through GHSL-2026-122 and CVEs including CVE-2026-48092, CVE-2026-48101, CVE-2026-48102, CVE-2026-48103, CVE-2026-48104, CVE-2026-48111, and CVE-2026-48112; the SDK path traversal bug could allow arbitrary file write and potentially lead to code execution in affected sample-app implementations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
GitHub Security Lab publicly disclosed details of the coordinated vulnerability report for 7-Zip 26.00 and older versions and the 7zDec sample extractor. The advisory described affected components including SquashFS, UEFI capsule and firmware parsing, UDF, WIM, and Ar handlers, and documented impacts such as out-of-bounds reads, uninitialized memory disclosure, integer overflow, denial of service, and arbitrary file write.
A fixed release, 7-Zip v26.01, was published to address the coordinatedly disclosed vulnerabilities affecting several archive handlers and the LZMA SDK sample extractor. The flaws were associated with GHSL advisories and CVEs including CVE-2026-48092, CVE-2026-48101, CVE-2026-48102, CVE-2026-48103, CVE-2026-48104, CVE-2026-48111, and CVE-2026-48112.
GitHub Security Lab researcher Jaroslav Lobačevski privately delivered a report covering multiple vulnerabilities in 7-Zip 26.00 and older versions, along with a path traversal issue in the 7zDec sample extractor from the LZMA SDK. The issues included memory access violations, denial of service conditions, and a sample-app arbitrary file write risk.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.