CVE-2026-27571: Unbounded Decompression Read
Reading an uncontrolled decompressed stream without limiting the output size can lead to excessive memory consumption and Out-Of-Memory (OOM) crashes, also known as a compression bomb or zip bomb. Wrap the decompressor with `io.LimitReader` or `io.LimitedReader` before reading into memory.
greprules fetch cve-2026-27571-unbounded-decompression-read --engine opengrepDescription
Reading an uncontrolled decompressed stream without limiting the output size can lead to excessive memory consumption and Out-Of-Memory (OOM) crashes, also known as a compression bomb or zip bomb. Wrap the decompressor with `io.LimitReader` or `io.LimitedReader` before reading into memory.
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.