CPython vulnerability

When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controlled size to pre-allocate memory, possibly resulting in memory exhaustion.

Published 25 Aug 2026Updated 11 Sep 20267 sources
CVSS 2.1

Source timeline

CVE record published by NVDView source ↗