CVE-2026-15310

EUVD-2026-65519
When decompressing crafted zip files using the bzip/LZMA/Zstandard 

compressions, Python could use an attacker-controlled size to 

pre-allocate memory, possibly resulting in memory exhaustion.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
PSFCNA
2.1 LOW
NETWORK
LOW
NONE
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N