Closed
Description
It is possible to upload zip bombs as wheels to PyPI, because Pythonzipfile
doesn't contain any tool to check for them (https://www.cvedetails.com/cve/CVE-2019-9674/)
It is possible to upload zip bombs as wheels to PyPI, because Pythonzipfile
doesn't contain any tool to check for them (https://www.cvedetails.com/cve/CVE-2019-9674/)