Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.8

CVE-2023-45853: MiniZip and pyminizip may allow attackers to crash systems with long file names

GHSA-mq29-j5xf-cjwr CVE-2023-45853 CVE-2023-45853
Summary

MiniZip and a version of pyminizip that bundles an affected zlib library may be vulnerable to a crash if an attacker uses a very long file name, comment, or extra field. This could potentially allow an attacker to disrupt normal system operations. If you use either of these tools, it's a good idea to update to a newer version that fixes this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
Ecosystem VendorProductAffected versions
pip pyminizip <= 0.2.6
zlib zlib < 1.3.1
cpe:2.3:a:zlib:zlib:*:*:*:*:*:*:*:*
smihica pyminizip <= 0.2.6
cpe:2.3:a:smihica:pyminizip:*:*:*:*:*:python:*:*
Original title
MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supporte...
Original description
MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.
ghsa CVSS3.1 9.8
Vulnerability type
CWE-190 Integer Overflow
Published: 14 Oct 2023 · Updated: 15 Jul 2026 · First seen: 6 Mar 2026