CodeChecker's massStoreRun processing path performs one-shot decompression of attacker-controlled, Base64-encoded zlib data without enforcing a maximum decompressed size. An authenticated user with permission to store analysis runs can submit a highly compressed payload that expands to a significantly larger byte sequence. Because the entire decompressed output is materialized in memory before being written to a temporary file, a sufficiently large payload may exhaust process or host memory and consume substantial disk space, resulting in denial of service.
History

Fri, 28 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Ericsson
Ericsson codechecker
Vendors & Products Ericsson
Ericsson codechecker

Fri, 28 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description CodeChecker's massStoreRun processing path performs one-shot decompression of attacker-controlled, Base64-encoded zlib data without enforcing a maximum decompressed size. An authenticated user with permission to store analysis runs can submit a highly compressed payload that expands to a significantly larger byte sequence. Because the entire decompressed output is materialized in memory before being written to a temporary file, a sufficiently large payload may exhaust process or host memory and consume substantial disk space, resulting in denial of service.
Title Authenticated Remote Denial of Service via Unbounded zlib Decompression in massStoreRun
Weaknesses CWE-409
CWE-770
References
Metrics cvssV4_0

{'score': 5.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/S:N/AU:Y/R:A/RE:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ERIC

Published: 2026-08-28T12:57:50.134Z

Updated: 2026-08-28T18:26:17.181Z

Reserved: 2026-06-29T10:41:35.472Z

Link: CVE-2026-58107

cve-icon Vulnrichment

Updated: 2026-08-28T18:26:12.696Z

cve-icon NVD

Status : Deferred

Published: 2026-08-28T16:18:18.293

Modified: 2026-09-01T21:07:58.980

Link: CVE-2026-58107

cve-icon Redhat

No data.