CVE-2026-15310: zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits

Overview

Severity
N/A
Exploit Status
Not Exploited
Patch Tuesday
2026-Aug
Released
2026-08-29
EPSS Score
0.30% (percentile: 22.6%)

Affected Products (2)

Other

  • 21694-17084
  • 21021-17084

Revision History

  • 2026-08-29: Information published.