
UpdatedJul 30, 2026
CVE-2026-14266 — Updated!
CVE-2026-14266 - XZ Heap Buffer Overflow PoC Generator for 7-Zip
CVE-2026-14266 Poc: 7-Zip XZ Heap Buffer Overflow PoC Generator
Proof of Concept generator for reproducing the XZ heap buffer overflow vulnerability in 7-Zip.
The script creates a specially crafted .xz archive designed to reproduce the crash condition in the vulnerable multi-threaded XZ decompression path.
Vulnerability Information
- CVE: CVE-2026-14266
- Type: Heap Buffer Overflow
- Fixed version: 26.02 or later
- Component: XZ Decoder
Features
- Generates a valid
.xzarchive from scratch - Reproduces the crash condition on vulnerable versions of 7-Zip
- No external archive generation tools required
Usage
python3 CVE-2026-14266.py
Output
poc-cve-2026-14266-crash.xz
Tested Environment
- Windows 11 x64
- 7-Zip 26.01 [https://github.com/ip7z/7zip/archive/refs/tags/26.01.zip]
☕ Support
If this project helped you, consider supporting its development:
USDT (TRC-20)
TDCPYioWbZW4iyMCuHhJeFsUZJ88YqZWc1
ETH (ERC-20)
0xf6eA555f95ed5b356fF7a90E6461EbBF6ce105cE