CVE-2023-22898: Circl Pandora
Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.
workers/extractor.py in Pandora (aka pandora-analysis/pandora) 1.3.0 allows a denial of service when an attacker submits a deeply nested ZIP archive (aka ZIP bomb).
Affected products
- Circl Pandora: before 1.3.1 (fixed in 1.3.1)
Published 2023-01-10. Last modified 2026-06-17.