CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2023-45853

Critical · CVSS 9.8

MiniZip / zlib / pyminizip — Integer overflow and heap-based buffer overflow in ZIP file creation (CWE-190)

CVSS
9.8
nvd
EPSS
2.92%
85th pct
KEV
No
Class
oss containerizable
CWE-190, CWE-190

Description

MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.

Search profile — drives PoC discovery

Symbols zipOpenNewFileInZip4_64zipOpenNewFileInZip4zipOpenNewFileInZipzip64local_putValuezip64local_TmzDateToDosDatepyminizip.compressminizipmz_zip_writer_add_filezipWriteInFileInZipsizeExtraFieldsizeCommentsizeFilename
Keywords CVE-2023-45853MiniZip integer overflowzlib MiniZip heap buffer overflowzipOpenNewFileInZip4_64 overflowpyminizip compress vulnerabilityzlib 1.3 minizip PoCpyminizip 0.2.6 CVEminizip long filename overflowminizip long comment overflowminizip extra field overflow
Versions: zlib <= 1.3; pyminizip <= 0.2.6

Ranked PoCs (58) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

Affected packages

PyPI pyminizip 0 → ∞

References

Status: enriched · ingested 2026-07-14T18:00:20.000Z · profiled 2026-07-14T18:30:20.000Z