CVE-2026-15310
When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controlled size to pre-allocate memory, possibly resulting in memory exhaustion.
- Published Aug 25, 2026
- CVSS 2.1 low
- 0.5% chance of exploitation in the next 30 days (EPSS)
- A fix is available