CVE-2023-45853Patch(smihica / pyminizip)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch smihica pyminizip systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-190

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pyminizip
  • zlib

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-11); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
pyminizipzlib

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-11: 1Mentions · 2026-07-22: 1Patch / Workaround · 2026-03-11: 103-1107-22
Signal classification2 categories
Patch
150.0%
General
150.0%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-03-111
Patch1
2026-07-221
General1
Full discourse2 posts
  • GCP Weekly@gcpweekly
    Patch

    CVE-2022-27943 CVE-2023-2953 CVE-2023-31437 CVE-2023-31438 CVE-2023-31439 CVE-2023-45853 CVE-2024-2236 CVE-2024-2379 CVE-2024-26458 CVE-2024-26461 CVE-2025-0725 CVE-2025-10148 CVE-2025-27587 CVE-2025-62813 CVE-2025-9086 CVE-2025-9230 CVE-2025-9232 N/A Security fixes for 10/19

    Post summary

    The post lists a set of CVE identifiers and notes that security fixes were issued on 10/19, indicating a focus on patch release rather than exploitation details.

    1000097
    1.8K followersView on X
  • BREACHSPIDER@breachspider
    General

    [CVE Analysis] CVE-2023-45853: Zlib and Foxit Flaws Expose Siemens CADRA Design Workstations https://breachspider.com/intel/2026-07-22-cve-2023-45853-zlib-and-foxit-flaws-expose-siemens-cadra-des #ICS #OTSecurity #SCADA #CriticalInfrastructure

    Post summary

    The post announces CVE-2023-45853, noting it involves zlib and Foxit flaws that could expose Siemens CADRA Design Workstations, but provides no deeper technical details, exploit code, or patch information.

    0000082
    2.3K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appsmihicapyminizip-python-
Appzlibzlib---

Explore more