Back to updates
UpdatedJul 30, 2026

CVE-2026-14266 — Updated!

CVE-2026-14266 - XZ Heap Buffer Overflow PoC Generator for 7-Zip

Share

CVE-2026-14266 Poc: 7-Zip XZ Heap Buffer Overflow PoC Generator

Proof of Concept generator for reproducing the XZ heap buffer overflow vulnerability in 7-Zip.

The script creates a specially crafted .xz archive designed to reproduce the crash condition in the vulnerable multi-threaded XZ decompression path.


Vulnerability Information

  • CVE: CVE-2026-14266
  • Type: Heap Buffer Overflow
  • Fixed version: 26.02 or later
  • Component: XZ Decoder

Features

  • Generates a valid .xz archive from scratch
  • Reproduces the crash condition on vulnerable versions of 7-Zip
  • No external archive generation tools required

Usage

python3 CVE-2026-14266.py

Output

poc-cve-2026-14266-crash.xz

Tested Environment


☕ Support

If this project helped you, consider supporting its development:

USDT (TRC-20)

TDCPYioWbZW4iyMCuHhJeFsUZJ88YqZWc1

USDT TRC-20 QR

ETH (ERC-20)

0xf6eA555f95ed5b356fF7a90E6461EbBF6ce105cE

Ethereum QR

References

Categories