🔐 CVE Alert

CVE-2026-58107

UNKNOWN 0.0

Authenticated Remote Denial of Service via Unbounded zlib Decompression in massStoreRun

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

CodeChecker's massStoreRun processing path performs one-shot decompression of attacker-controlled, Base64-encoded zlib data without enforcing a maximum decompressed size. An authenticated user with permission to store analysis runs can submit a highly compressed payload that expands to a significantly larger byte sequence. Because the entire decompressed output is materialized in memory before being written to a temporary file, a sufficiently large payload may exhaust process or host memory and consume substantial disk space, resulting in denial of service.

CWE CWE-409 CWE-770
Vendor ericsson
Product codechecker
Published Aug 28, 2026
Stay Ahead of the Next One

Get instant alerts for ericsson codechecker

Be the first to know when new unknown vulnerabilities affecting ericsson codechecker are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Ericsson / CodeChecker
0 < 6.28.3

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/Ericsson/codechecker/security/advisories/GHSA-w7jw-x567-hqr4

Credits

Nir Yehoshua, Cipher Security Labs