Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xj79-6hh5-9w6q

Опубликовано: 25 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 2.1

Описание

When decompressing crafted zip files using the bzip/LZMA/Zstandard

compressions, Python could use an attacker-controlled size to

pre-allocate memory, possibly resulting in memory exhaustion.

When decompressing crafted zip files using the bzip/LZMA/Zstandard

compressions, Python could use an attacker-controlled size to

pre-allocate memory, possibly resulting in memory exhaustion.

EPSS

Процентиль: 34%
0.00399
Низкий

2.1 Low

CVSS4

Дефекты

CWE-400

Связанные уязвимости

ubuntu
28 дней назад

When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controlled size to pre-allocate memory, possibly resulting in memory exhaustion.

nvd
28 дней назад

When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controlled size to pre-allocate memory, possibly resulting in memory exhaustion.

msrc
24 дня назад

zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits

debian
28 дней назад

When decompressing crafted zip files using the bzip/LZMA/Zstandard c ...

EPSS

Процентиль: 34%
0.00399
Низкий

2.1 Low

CVSS4

Дефекты

CWE-400