Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-15310

Опубликовано: 29 авг. 2026
Источник: msrc
EPSS Низкий

Описание

zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits

Обновления

ПродуктСтатьяОбновление
azl3 python3 3.12.14-1 on Azure Linux 3.0
azl3 python3 3.12.9-14 on Azure Linux 3.0

Показывать по

EPSS

Процентиль: 34%
0.00399
Низкий

Связанные уязвимости

ubuntu
28 дней назад

When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controlled size to pre-allocate memory, possibly resulting in memory exhaustion.

nvd
28 дней назад

When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controlled size to pre-allocate memory, possibly resulting in memory exhaustion.

debian
28 дней назад

When decompressing crafted zip files using the bzip/LZMA/Zstandard c ...

github
28 дней назад

When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controlled size to pre-allocate memory, possibly resulting in memory exhaustion.

EPSS

Процентиль: 34%
0.00399
Низкий