The following vulnerabilities were published for 7zip.
CVE-2025-53816[0]:
| 7-Zip is a file archiver with a high compression ratio. Zeroes
| written outside heap buffer in RAR5 handler may lead to memory
| corruption and denial of service in versions of 7-Zip prior to
| 25.0.0. Version 25.0.0 contains a fix for the issue.
CVE-2025-53817[1]:
| 7-Zip is a file archiver with a high compression ratio. 7-Zip
| supports extracting from Compound Documents. Prior to version
| 25.0.0, a null pointer dereference in the Compound handler may lead
| to denial of service. Version 25.0.0 contains a fix cor the issue.
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.