boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-48095HIGH
mcmilk 7-Zip — GHSL-2026-140_7-Zip: 7-Zip has a heap buffer overflow via NTFS compressed stream buffer under-allocation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0112   63.5     —
AFFECTED
  Product  Versions    Fixed
  7-Zip    <= 26.00 –  —
TIMELINE
  May 20  Reserved by GitHub_M
  Jun 5   EXPLOIT PUBLISHED — CVE-2026-48095 (mcmilk 7-Zip). Public exploit reference added.
  Jun 5   Published (CNA: GitHub_M)
CWE-190, CWE-787 · CNA: GitHub_M · CVSS v3.1 · 2 references · NVD status: Modified

Description

7-Zip is a file archiver with a high compression ratio. Versions 26.00 and prior contain a heap buffer overflow vulnerability caused by an under-allocation in the NTFS compressed stream buffer (GetCuSize shift UB), potentially allowing attackers to cause arbitrary code execution or application crashes. CInStream::GetCuSize() in the NTFS handler computes the compression-unit buffer size as (UInt32)1 << (BlockSizeLog + CompressionUnit), and a crafted image with ClusterSizeLog >= 28 and CompressionUnit == 4 drives the exponent to 32, which is undefined behavior and collapses on x86/x64 so _inBuf is allocated as 1 byte. ReadStream_FALSE then writes up to 256 MB of attacker-controlled data into that 1-byte buffer in 64 KB iterations, and because the CInStream object sits only 304 bytes after _inBuf, its vtable pointer is overwritten and the next dispatched call achieves a vtable hijack. On 32-bit builds the overflow is unconditionally reached; on 64-bit it requires the parallel 8 GB _outBuf allocation to succeed, otherwise failing closed to denial of service. The NTFS handler is enabled by default in stock 7z.dll and, via signature-based fallback matching "NTFS " at offset 3, will open a crafted image regardless of file extension during extraction or testing. Version 26.01 fixes the issue.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
May 20, 2026ReservedReserved by GitHub_M
June 5, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2026-48095 (mcmilk 7-Zip). Public exploit reference added.
June 5, 2026PublishedPublished (CNA: GitHub_M)

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
mcmilk7-Zip<= 26.00

Weaknesses

CWE-190 · CWE-787

References (2)

Related

Authoritative record: CVE-2026-48095 at cve.org

Vendors: mcmilk

Weaknesses: CWE-190 · CWE-787

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-48095 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.