A vulnerability in Python libraries lzma, bz2, and gzip, which could potentially lead to code execution.

The delivered classes in CPython for decompressing data in lzma, bz2, and gzip formats (lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile) have a vulnerability (CVE-2026-6100) that leads to accessing memory after it has been freed. The issue has been assigned a critical severity level (9.1 out of 10) — if successfully exploited, this vulnerability could result in leaking information from the process’s memory or executing the attacker’s code when decompressing specially crafted data. A fix is currently available in the form of a patch.

The problem manifests after the memory allocation operation is terminated by an error occurring due to insufficient memory (for the vulnerability to be successfully exploited, the attacker must create conditions that exhaust the memory available to the process). Accessing already freed memory occurs in applications that reuse an object instance after an error is returned during decompression. Applications that create a new object instance on each call are not susceptible to the vulnerability.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster