CVE-2026-22870: GuardDog Zip Bomb Vulnerability in safe_extract() Allows DoS
GuardDog’s safe_extract() function does not validate decompressed file sizes when extracting ZIP archives (wheels, eggs), allowing attackers to cause denial of service through zip bombs. A malicious package can consume gigabytes of disk space from a few megabytes of compressed data.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-22870 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →