LOW 2.1 NVD
CVE-2026-15310
When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controlled size to pre-allocate memory, possib
When decompressing crafted zip files using the bzip/LZMA/Zstandard
compressions, Python could use an attacker-controlled size to
pre-allocate memory, possibly resulting in memory exhaustion.
References
- https://github.com/python/cpython/issues/156002
- https://github.com/python/cpython/pull/156003
- https://mail.python.org/archives/list/security-announce@python.org/thread/YUHXURX2WZGKGNA4
This low severity vulnerability with a CVSS score of 2.1 was published on 2026-08-25 via NVD.
vulnfeed aggregates 11954 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.