---
id: CVE-2019-9674
title: >-
  Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a
  denial of service (resource consumption) via a ZIP bomb.
summary: >-
  Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a
  denial of service (resource consumption) via a ZIP bomb.
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-400
vendor: python
product: python
affected:
  - 'python >= 3.2, <= 3.8'
  - ubuntu_linux = 12.04
  - ubuntu_linux = 14.04
  - ubuntu_linux = 16.04
  - ubuntu_linux = 18.04
  - ubuntu_linux = 20.04
  - active_iq_unified_manager
published: '2020-02-04'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:17:20.360'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-9674'
references:
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00003.html'
    label: cve@mitre.org
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00041.html'
    label: cve@mitre.org
  - url: 'https://bugs.python.org/issue36260'
    label: cve@mitre.org
  - url: 'https://bugs.python.org/issue36462'
    label: cve@mitre.org
  - url: 'https://github.com/python/cpython/blob/master/Lib/zipfile.py'
    label: cve@mitre.org
  - url: 'https://python-security.readthedocs.io/security.html#archives-and-zip-bomb'
    label: cve@mitre.org
  - url: 'https://security.netapp.com/advisory/ntap-20200221-0003/'
    label: cve@mitre.org
  - url: 'https://usn.ubuntu.com/4428-1/'
    label: cve@mitre.org
  - url: 'https://www.python.org/news/security/'
    label: cve@mitre.org
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00003.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00041.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://bugs.python.org/issue36260'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://bugs.python.org/issue36462'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/python/cpython/blob/master/Lib/zipfile.py'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://python-security.readthedocs.io/security.html#archives-and-zip-bomb'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20200221-0003/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://usn.ubuntu.com/4428-1/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.python.org/news/security/'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.05535
epssPercentile: 0.92612
ingestedAt: '2026-10-08T22:11:53.710Z'
---

## Overview

Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb.

## Affected

- `python >= 3.2, <= 3.8`
- `ubuntu_linux = 12.04`
- `ubuntu_linux = 14.04`
- `ubuntu_linux = 16.04`
- `ubuntu_linux = 18.04`
- `ubuntu_linux = 20.04`
- `active_iq_unified_manager`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
