Description
Pandora contains a denial-of-service vulnerability in its handling of DAA (Direct Access Archive) files. When extracting the internal ISO image from a DAA archive, compressed chunks were decompressed using zlib.decompress() without enforcing a limit on the resulting uncompressed data.


An attacker able to submit a crafted DAA file containing highly compressed data could cause Pandora to decompress a relatively small input into a very large amount of data in memory. Because the decompressed chunks are accumulated to construct the internal ISO image, this could result in excessive memory consumption and potentially CPU exhaustion, causing the extraction worker to become unresponsive, terminate, or affect the availability of the Pandora service.


The patch introduces bounded decompression using decompressobj().decompress() with max_extracted_filesize, verifies the cumulative size of decompressed chunks, and raises a dedicated ZipBomb exception when the configured limit is exceeded. Pandora then aborts extraction and reports the file as too large.
Published: 2026-08-15
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Pandora's handling of DAA files allows an attacker to craft a file containing highly compressed data that is decompressed without size limits, causing excessive memory and CPU usage which can force the extraction worker to stop or become unresponsive, resulting in a denial of service.

Affected Systems

Pandora by Pandora Analysis is the affected product. No specific versions are listed in the CNA data, but any release that has not applied the patch for bounded decompression may be vulnerable.

Risk and Exploitability

With a CVSS score of 8.7, this is a high‑severity vulnerability. It is inferred that the attack vector involves a remote file upload, as the vulnerability is triggered by an attacker submitting a malicious DAA file. No EPSS estimate is available and the vulnerability is not currently listed in CISA's KEV. Exploitation would require only the ability to provide a DAA file to Pandora's extraction service, which could result in memory exhaustion and service degradation.

Generated by OpenCVE AI on August 15, 2026 at 23:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Pandora to the version that implements bounded decompression using decompressobj() with max_extracted_filesize.
  • Set configuration to enforce a maximum extracted file size limit and monitor usage.
  • If patch not yet available, temporarily block or refuse large DAA uploads and quarantine suspicious files.

Generated by OpenCVE AI on August 15, 2026 at 23:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Pandora-analysis
Pandora-analysis pandora
Vendors & Products Pandora-analysis
Pandora-analysis pandora

Sat, 15 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description Pandora contains a denial-of-service vulnerability in its handling of DAA (Direct Access Archive) files. When extracting the internal ISO image from a DAA archive, compressed chunks were decompressed using zlib.decompress() without enforcing a limit on the resulting uncompressed data. An attacker able to submit a crafted DAA file containing highly compressed data could cause Pandora to decompress a relatively small input into a very large amount of data in memory. Because the decompressed chunks are accumulated to construct the internal ISO image, this could result in excessive memory consumption and potentially CPU exhaustion, causing the extraction worker to become unresponsive, terminate, or affect the availability of the Pandora service. The patch introduces bounded decompression using decompressobj().decompress() with max_extracted_filesize, verifies the cumulative size of decompressed chunks, and raises a dedicated ZipBomb exception when the configured limit is exceeded. Pandora then aborts extraction and reports the file as too large.
Title Unbounded DAA Decompression in Pandora Allows Denial of Service via Decompression Bomb
Weaknesses CWE-434
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L'}


Subscriptions

Pandora-analysis Pandora
cve-icon MITRE

Status: PUBLISHED

Assigner: CIRCL

Published:

Updated: 2026-08-17T19:40:15.307Z

Reserved: 2026-08-15T21:56:41.828Z

Link: CVE-2026-74767

cve-icon Vulnrichment

Updated: 2026-08-17T19:40:09.524Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-15T22:16:55.697

Modified: 2026-08-26T16:49:35.390

Link: CVE-2026-74767

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T10:59:17Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type