CVE-2026-15310: Python Software Foundation Cpython
Low severity, CVSS 2.1. EPSS: 0.5% chance of exploitation in the next 30 days.
When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controlled size to pre-allocate memory, possibly resulting in memory exhaustion.
Affected products
- Python Software Foundation Cpython: before 3.10.22 (fixed in 3.10.22); from 3.11.0, before 3.11.17 (fixed in 3.11.17); from 3.12.0, before 3.12.15 (fixed in 3.12.15); from 3.13.0, before 3.13.16 (fixed in 3.13.16); from 3.14.0, before 3.14.8 (fixed in 3.14.8); from 3.15.0a1, before 3.15.0rc2 (fixed in 3.15.0rc2)
Published 2026-08-25. Last modified 2026-10-02.