GuardDog is a CLI tool to identify malicious PyPI packages. Prior to 2.7.1, GuardDog's safe_extract() function does not validate decompressed file sizes when extracting ZIP archives (wheels, eggs), allowing attackers to cause denial of service through zip bombs. A malicious package can consume gigabytes of disk space from a few megabytes of compressed data. This vulnerability is fixed in 2.7.1.
Cite this page
CVE-2026-22870. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2026-22870
Use CWE-409, Datadoghq vendor hub and Guarddog product page to widen CVE-2026-22870 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-22871, CVE-2022-23531 and CVE-2022-23530 for nearby disclosures in the same product family.