CVE-2026-22870
HIGHdatadoghq/guarddog < 2.7.1 - Denial of Service via ZIP Bomb Extraction
Title source: llmDescription
GuardDog is a CLI tool to identify malicious PyPI packages. Prior to 2.7.1, GuardDog's safe_extract() function does not validate decompressed file sizes when extracting ZIP archives (wheels, eggs), allowing attackers to cause denial of service through zip bombs. A malicious package can consume gigabytes of disk space from a few megabytes of compressed data. This vulnerability is fixed in 2.7.1.
References (2)
Core 2
Core References
Third Party Advisory, Exploit x_refsource_confirm
https://github.com/DataDog/guarddog/security/advisories/GHSA-ffj4-jq7m-9g6v
Scores
CVSS v3
7.5
EPSS
0.0005
EPSS Percentile
15.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-409
Status
published
Products (2)
datadoghq/guarddog
< 2.7.1
pypi/guarddog
0 - 2.7.1PyPI
Published
Jan 13, 2026
Tracked Since
Feb 18, 2026