CVE-2025-53816: 7-Zip

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

7-Zip is a file archiver with a high compression ratio. Zeroes written outside heap buffer in RAR5 handler may lead to memory corruption and denial of service in versions of 7-Zip prior to 25.0.0. Version 25.0.0 contains a fix for the issue.

Affected products

  • 7-Zip 7-Zip: before 25.00 (fixed in 25.00)

Published 2025-07-17. Last modified 2026-06-17.