CodeChecker's massStoreRun processing path performs one-shot decompression of attacker-controlled, Base64-encoded zlib data without enforcing a maximum decompressed size.
An authenticated user with permission to store analysis runs can submit a highly compressed payload that expands to a significantly larger byte sequence. Because the entire decompressed output is materialized in memory before being written to a temporary file, a sufficiently large payload may exhaust process or host memory and consume substantial disk space, resulting in denial of service.
Metrics
Affected Vendors & Products
References
History
Fri, 28 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 28 Aug 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ericsson
Ericsson codechecker |
|
| Vendors & Products |
Ericsson
Ericsson codechecker |
Fri, 28 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CodeChecker's massStoreRun processing path performs one-shot decompression of attacker-controlled, Base64-encoded zlib data without enforcing a maximum decompressed size. An authenticated user with permission to store analysis runs can submit a highly compressed payload that expands to a significantly larger byte sequence. Because the entire decompressed output is materialized in memory before being written to a temporary file, a sufficiently large payload may exhaust process or host memory and consume substantial disk space, resulting in denial of service. | |
| Title | Authenticated Remote Denial of Service via Unbounded zlib Decompression in massStoreRun | |
| Weaknesses | CWE-409 CWE-770 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: ERIC
Published: 2026-08-28T12:57:50.134Z
Updated: 2026-08-28T18:26:17.181Z
Reserved: 2026-06-29T10:41:35.472Z
Link: CVE-2026-58107
Updated: 2026-08-28T18:26:12.696Z
Status : Deferred
Published: 2026-08-28T16:18:18.293
Modified: 2026-09-01T21:07:58.980
Link: CVE-2026-58107
No data.