CVE-2026-15310

When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controlled size to pre-allocate memory, possibly resulting in memory exhaustion.

Scoring

Severity
LOW
CVSS base score
2.1
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
EPSS probability
0.35%
CWE
CWE-400
Published
2026-08-25
Last modified
2026-09-17

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs