CVEPublished 2026-08-28Modified 2026-09-010 articles on news7 live referencesNVD data

CVE-2026-58107

Vulnerability data via NVD (ingested)

CVSS v3.1
EPSS percentile
22
Exploit Prediction Scoring System · top 78% of all CVEs
Description

CodeChecker's massStoreRun processing path performs one-shot decompression of attacker-controlled, Base64-encoded zlib data without enforcing a maximum decompressed size. An authenticated user with permission to store analysis runs can submit a highly compressed payload that expands to a significantly larger byte sequence. Because the entire decompressed output is materialized in memory before being written to a temporary file, a sufficiently large payload may exhaust process or host memory and consume substantial disk space, resulting in denial of service.

Timeline
Published 2026-08-28
Modified 2026-09-01

External references

Search for exposed instances

Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).

More intel sources (5)

Known PoCs on GitHub

No public proof-of-concept repositories found for CVE-2026-58107 on GitHub.
We haven't classified any articles referencing CVE-2026-58107 yet. The external references above still apply.