216.73.216.36

CVE-2026-22870

· Published 13/01/2026 21:15 · Modified 14/01/2026 16:25

Labels: CVE-2026-22870 2026-01-13CVE-2026-22870CWE-409[email protected]

Essential information

Published
13/01/2026 21:15
Modified
14/01/2026 16:25
Author
Creator
CVSS
7.1 HIGH (v3) 7.1 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

GuardDog is a CLI tool to identify malicious PyPI packages. Prior to 2.7.1, GuardDog's safe_extract() function does not validate decompressed file sizes when extracting ZIP archives (wheels, eggs), allowing attackers to cause denial of service through zip bombs. A malicious package can consume gigabytes of disk space from a few megabytes of compressed data. This vulnerability is fixed in 2.7.1.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
guarddog / guarddog cpe:2.3:a:guarddog:guarddog:2.7.1:*:*:*:*:*:*:*
guarddog / guarddog cpe:2.3:a:guarddog:guarddog:*:*:*:*:*:*:*:*

References