# CVE-2026-15310

## Summary

- **CVE ID:** CVE-2026-15310
- **Severity:** LOW
- **CVSS Score:** 2.1 (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N)
- **CWE:** CWE-400
- **Published:** Aug 25, 2026
- **Last Modified:** Sep 17, 2026

## Description

When decompressing crafted zip files using the bzip/LZMA/Zstandard 

compressions, Python could use an attacker-controlled size to 

pre-allocate memory, possibly resulting in memory exhaustion.

## Affected Products

- Python Software Foundation — CPython (0)

## References

- [CNA](https://github.com/python/cpython/pull/156003)
- [CNA](https://github.com/python/cpython/issues/156002)
- [CNA](https://mail.python.org/archives/list/security-announce@python.org/thread/YUHXURX2WZGKGNA4ANYBQS2VZRYQ5JNK/)
- [CNA](https://github.com/python/cpython/commit/f897dbf2f36a5935700b7c2d94d4681d2136b7d4)
- [CNA](https://github.com/python/cpython/commit/1b424c0178a01e155fd0267dc28a8fc1159b33a8)
- [CNA](https://github.com/python/cpython/commit/31980e84b9a708424a0a1dfecde3fc991e313f89)
- [CNA](https://github.com/python/cpython/commit/e2311cfb3dd518f008f312fe0631f4f7490d237a)
- [CNA](https://github.com/python/cpython/commit/f507e6946a3194e83e1d7b8ee6e14567175e46de)
- [CNA](https://github.com/python/cpython/commit/9d167992b59cf5e23c66b9ed742b13f5925f7d70)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.40%
- **EPSS Percentile:** 33.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._