CVE-2026-15310

Summary

When decompressing crafted zip files using the bzip/LZMA/Zstandard

compressions, Python could use an attacker-controlled size to

pre-allocate memory, possibly resulting in memory exhaustion.

Affected Software

VendorProductVersion RangeStatus
Python Software FoundationCPython0 < 3.10.22affected
Python Software FoundationCPython3.11.0 < 3.11.17affected
Python Software FoundationCPython3.12.0 < 3.12.15affected
Python Software FoundationCPython3.13.0 < 3.13.16affected
Python Software FoundationCPython3.14.0 < 3.14.8affected
Python Software FoundationCPython3.15.0a1 < 3.15.0rc2affected

Weaknesses

  • CWE-400: CWE-400

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References