CVE-2026-15310
Severity CVSS v4.0:
LOW
Type:
CWE-400
Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
25/08/2026
Last modified:
26/08/2026
Description
When decompressing crafted zip files using the bzip/LZMA/Zstandard <br />
<br />
compressions, Python could use an attacker-controlled size to <br />
<br />
pre-allocate memory, possibly resulting in memory exhaustion.
Impact
Base Score 4.0
2.10
Severity 4.0
LOW



