Impact
Pandora's handling of DAA files allows an attacker to craft a file containing highly compressed data that is decompressed without size limits, causing excessive memory and CPU usage which can force the extraction worker to stop or become unresponsive, resulting in a denial of service.
Affected Systems
Pandora by Pandora Analysis is the affected product. No specific versions are listed in the CNA data, but any release that has not applied the patch for bounded decompression may be vulnerable.
Risk and Exploitability
With a CVSS score of 8.7, this is a high‑severity vulnerability. It is inferred that the attack vector involves a remote file upload, as the vulnerability is triggered by an attacker submitting a malicious DAA file. No EPSS estimate is available and the vulnerability is not currently listed in CISA's KEV. Exploitation would require only the ability to provide a DAA file to Pandora's extraction service, which could result in memory exhaustion and service degradation.
OpenCVE Enrichment