Skip to content

Zip Bomb protection for wheels #10504

Closed
Closed
@abitrolly

Description

@abitrolly

It is possible to upload zip bombs as wheels to PyPI, because Pythonzipfile doesn't contain any tool to check for them (https://www.cvedetails.com/cve/CVE-2019-9674/)

Blocks #9972 which fixes #8254.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bug 🐛securitySecurity-related issues and pull requests

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions