VDB

CVE-2026-15310

CVE-2026-15310 PUBLISHED CVSS 2.1 LOW

Reported by PSF · Published August 25, 2026

When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controlled size to pre-allocate memory, possibly resulting in memory exhaustion.

Risk Scores

CVSS 4.0
2.1
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
Python Software FoundationCPython0, 3.11.0, 3.12.0
wolfipython-3.130, 0, 0
chainguardpython-3.120, 0
chainguardpython-3.130, 0
chainguardpython-3.100, 0
alpinepython30, 0, 0
wolfipython-3.140, 0, 0
wolfipython-3.100, 0, 0
chainguardpython-3.140, 0, 0
Python Software FoundationCPython3.15.0a1, 3.15.0a1, 0
wolfipython-3.120, 0, 0
wolfipython-3.110, 0
chainguardpython-3.110

Timeline

  • Aug 25, 2026 CVE Published
  • Aug 26, 2026 EPSS Score
  • Sep 2, 2026 EPSS Score
  • Sep 2, 2026 Security Advisory
  • Sep 4, 2026 EPSS Score
  • Sep 9, 2026 EPSS Score
  • Sep 11, 2026 EPSS Score
  • Sep 12, 2026 EPSS Score
  • Sep 16, 2026 EPSS Score
  • Sep 17, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score
  • Sep 24, 2026 EPSS Score

References

  • patch
  • issue-tracking
  • vendor-advisory
  • patch
  • patch
  • patch
  • patch
  • patch
  • patch
  • patch
  • patch
  • patch
  • patch
Open in Interactive Console →
$ Console Community · 100/wk Open console ›