CVE-2026-481127-zip · 7-zip
Vulnerability data via NVD (ingested)
7-Zip is a file archiver with a high compression ratio. Versions 9.18 through 26.00 contain a heap out-of-bounds read in 7-Zip Ar handler BSD SYMDEF parser. A 4-byte heap out-of-bounds read exists in the Unix ar archive parser in 7-Zip. When parsing a BSD-style __.SYMDEF symbol table, the ParseLibSymbols function reads a 32-bit namesSize field via Get32 at a position that can equal the buffer size, reading 4 bytes past the end of the heap allocation. This reads uninitialized heap data under the default allocator. Version 26.01 patches the issue.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-48112product:"7-zip 7-zip"http.html:"7-zip"More intel sources (5)
vuln:CVE-2026-48112vulnerabilities.cve_id: CVE-2026-48112CVE-2026-48112CVE-2026-48112"CVE-2026-48112" exploit -site:nvd.nist.gov