CVE-2026-102514
Last modified
CVE-2026-102514 is a high-severity vulnerability rated 8.4/10 on the CVSS scale. Out-of-bounds Write (CWE-787) in the PEA archive extraction routine (pea.pas, unpea_procedure) of the first-party pea component in PeaZip 11.2.0 and earlier allows an attacker who convinces a victim to open or extract a crafted .pea archive to execute arbitrary code as the user running PeaZip. While decompressing a PCOMPRESS1 stream, the 32-bit compressed-block-size field of the first block (compsize) is read directly from the archive and used without validation as the length of a blockread into the fixed-size global buffers wbuf1/wbuf2 (1,114,112 bytes) and as the bound of the subsequent copy loop. EPSS estimates a 0.13% chance of exploitation in the next 30 days.
Description
Out-of-bounds Write (CWE-787) in the PEA archive extraction routine (pea.pas, unpea_procedure) of the first-party pea component in PeaZip 11.2.0 and earlier allows an attacker who convinces a victim to open or extract a crafted .pea archive to execute arbitrary code as the user running PeaZip. While decompressing a PCOMPRESS1 stream, the 32-bit compressed-block-size field of the first block (compsize) is read directly from the archive and used without validation as the length of a blockread into the fixed-size global buffers wbuf1/wbuf2 (1,114,112 bytes) and as the bound of the subsequent copy loop. The existing check "compsize > WBUFSIZE" is applied only to the size of each following block, so the first block escapes it; the same unvalidated value is also used to index wbuf1[compsize], an out-of-bounds read at an attacker-chosen offset. The copy loop additionally copies the requested length instead of the number of bytes actually read, and terminates on equality rather than on an upper bound. Because the project is built without range checking and no archive password, integrity tag or non-default configuration is required, the overflow overwrites adjacent global data; code execution was demonstrated by two independent researchers against the official Linux x86-64 and Windows x64 builds, and the denial-of-service and memory-corruption primitive is cross-platform (Windows, macOS, Linux, BSD).
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| PeaZip | PeaZip | < 11.3.0 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-102514?
How severe is CVE-2026-102514?
How do I fix CVE-2026-102514?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-102507Sliver C2 framework version 1.7.7 and earlier contains an un…5.7
- CVE-2026-102508Improper Verification of Cryptographic Signature and Imprope…9.2
- CVE-2026-102509Memory Allocation with Excessive Size Value, Allocation of R…8.7
- CVE-2026-10251A weakness has been identified in itsourcecode Online House …7.3
- CVE-2026-102510Integer Overflow, Improper Validation of Array Index, Uncont…8.7
- CVE-2026-102511Improper Verification of Source of a Communication Channel i…8.5
- CVE-2026-10252A security vulnerability has been detected in itsourcecode O…7.3
- CVE-2026-102521The decoder in `readFromDataView` in lib0 before 0.2.119 can…8.6
- CVE-2026-10253A vulnerability was detected in itsourcecode Online House Re…7.3
- CVE-2026-10254A flaw has been found in SourceCodester Pet Grooming Managem…5.5
- CVE-2026-10255A vulnerability has been found in SourceCodester Pharmacy Sa…5.5
- CVE-2026-102555A flaw was found in libsoup. The soup_uri_decode_data_uri() …8.2
Are you affected by CVE-2026-102514?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
