CVE-2019-9674: High severity Python Python vulnerability
Last updated 18 August 2025
Other sources
Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-9674?
CVE-2019-9674 is a vulnerability in Lib/zipfile.py in Python through 3.7.2 that allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb.
What is the severity of CVE-2019-9674?
CVE-2019-9674 has a severity level of 7.5 (high).
Is Python 2.7 affected by CVE-2019-9674?
Yes, Python 2.7 is affected by CVE-2019-9674. The vulnerable versions are 2.7.17-1~18.04ubuntu1.1 and 2.7.18-1~20.04.1.
Is Python 3.7 affected by CVE-2019-9674?
Yes, Python 3.7 is affected by CVE-2019-9674. The vulnerable versions are up to and including 3.7.2.
How can I fix CVE-2019-9674?
To fix CVE-2019-9674, you need to update Python to a version that has the security patches for this vulnerability. For Python 2.7, update to version 2.7.17-1~18.04ubuntu1.1 or 2.7.18-1~20.04.1. For Python 3.7, update to a version higher than 3.7.2.