PT-2026-73062 · Pandora · Pandora

·

CVE-2026-74767

·

Published

2026-08-15

·

Updated

2026-08-17

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Pandora (affected versions not specified)
Description Pandora contains a denial-of-service issue in its handling of DAA (Direct Access Archive) files. During the extraction of an internal ISO image from a DAA archive, the system uses the zlib.decompress() function to process compressed chunks without enforcing a limit on the resulting uncompressed data. An attacker can submit a crafted DAA file containing highly compressed data, causing the system to expand a small input into an excessively large amount of data in memory. This process can lead to extreme memory consumption and CPU exhaustion, which may cause the extraction worker to become unresponsive or terminate, impacting the overall availability of the service. This type of attack is known as a decompression bomb, where a small file is designed to consume vast amounts of system resources upon decompression.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-74767

Affected Products

Pandora