CVE-2026-107335

CVE-2026-107335 published: Malcolm's upload-processing pipeline (scripts/safe-extract.py) enforces entry-count, nesting-depth, and total-uncompressed-byte limits when extracting container archives (zip/tar/rar/7z via libarchive), but those limits are not applied when the uploaded fil...

View full NVD advisory → ← Back to CVE watch