CVE-2023-22898: Circl Pandora

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

workers/extractor.py in Pandora (aka pandora-analysis/pandora) 1.3.0 allows a denial of service when an attacker submits a deeply nested ZIP archive (aka ZIP bomb).

Affected products

  • Circl Pandora: before 1.3.1 (fixed in 1.3.1)

Published 2023-01-10. Last modified 2026-06-17.