CVE-2026-6100Disclosure

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered if the process is under memory pressure. The fix cleans up the dangling pointer in this specific error condition. The vulnerability is only present if the program re-uses decompressor instances across multiple decompression calls even after a `MemoryError` is raised during decompression. Using the helper functions to one-shot decompress data such as `lzma.decompress()`, `bz2.decompress()`, `gzip.decompress()`, and `zlib.decompress()` are not affected as a new decompressor instance is used per call. If the decompressor instance is not re-used after an error condition, this usage is similarly not vulnerable.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416CWE-787CWE-825

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 11 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • General: 2 classified signals
  • Peaked 6d ago at 3 mentions (2026-04-13); latest day: 1
  • 11 total mentions across 7 days

Deep dive

Activity timeline11 mentions / 7d
01223Mentions · 2026-04-13: 3Mentions · 2026-04-14: 2Mentions · 2026-04-15: 1Mentions · 2026-04-20: 2Mentions · 2026-04-28: 1Mentions · 2026-07-17: 1Mentions · 2026-08-05: 1Patch / Workaround · 2026-04-20: 1Patch / Workaround · 2026-04-28: 1Patch / Workaround · 2026-07-17: 1Patch / Workaround · 2026-08-05: 1Technical Details · 2026-04-13: 2Technical Details · 2026-04-20: 2Technical Details · 2026-04-28: 1Technical Details · 2026-07-17: 104-1304-1404-1504-2004-2807-1708-05
Signal classification3 categories
Disclosure
545.5%
Patch
436.4%
General
218.2%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-04-133
Disclosure3
2026-04-142
General2
2026-04-151
Disclosure1
2026-04-202
Disclosure1Patch1
2026-04-281
Patch1
2026-07-171
Patch1
2026-08-051
Patch1
Full discourse11 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-6100: CPython: Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after reuse under memory pressure https://www.openwall.com/lists/oss-security/2026/04/13/10 Critical severity, but only present if the program reuses decompressor instances across calls even after a MemoryError

    Post summary

    A new CVE for CPython’s decompression modules is disclosed, describing a critical use‑after‑free triggered by memory pressure when reusing decompressor instances.

    1201121.3K
    4.6K followersView on X
  • Kazuki Omo@omokazuki
    Disclosure

    SIOSセキュリティブログを更新しました。 Pythonの脆弱性(High: CVE-2026-6100) #sios_tech #security #vulnerability #セキュリティ #脆弱性 #python https://security.sios.jp/vulnerability/python-security-vulnerability-20260416/

    Post summary

    The post announces a high‑severity Python vulnerability (CVE‑2026‑6100) via a blog link, but provides no further technical or mitigation details.

    00010145
    361 followersView on X
  • MalwareObserver@MalwareObserver
    Patch

    🐛 VULNERABILITIES CVE Notify: 🚨 [CVE-2026-6100](https://github.com/python/cpython/commit/47128e64f98c3a20271138a98c2922bea2a3ee0e... https://github.com/python/cpython/commit/47128e64f98c3a20271138a98c2922bea2a3ee0e #ZeroDay #PatchManagement #Vulnerability

    Post summary

    The tweet alerts readers to CVE-2026-6100 and links to a GitHub commit that appears to contain the patch, but offers no exploit details or technical description.

    0000057
    17 followersView on X
  • VulniPulse@vulnipulse
    Patch

    ⚠️ NetApp Active IQ Unified Manager for Microsoft Windows alert: CVE-2026-6100 (CVSS 9.1) Attackers could affect the listed product. No workaround; upgrade to a vendor-listed fixed release. https://vulnipulse.com/advisories/netapp-ntap-20260717-0015 #NetApp #CyberSecurity #CVE

    Post summary

    The tweet announces CVE‑2026‑6100 against NetApp Active IQ Unified Manager for Windows, provides its severity score, and urges users to apply the vendor‑released patch, but gives no PoC, exploit details, or evidence of active exploitation.

    0000035
    6 followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Fedora updates MinGW Windows python3 to patch CVE-2026-4786, CVE-2026-6100, CVE-2026-3479, CVE-2026-1502 enabling code execution, data leaks, and HTTP header injection. https://threatcluster.io/cluster/multiple-cves-addressed-in-fedora-python3-updates-f6a2a99b

    Post summary

    The news announces Fedora’s update of MinGW Windows python3 to patch four CVEs that could enable code execution, data leaks, and HTTP header injection, with no mention of active exploitation or PoC.

    0000063
    166 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6100 Use-After-Free in Python Decompressor Modules Following Memory Allocation Failure https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6100

    Post summary

    The post announces CVE‑2026‑6100, detailing a use‑after‑free flaw in Python’s decompression modules, without referencing PoC, exploit code, or active exploitation.

    0000043
    4.0K followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Critical Python flaws CVE-2026-1502 and CVE-2026-6100 hit 3.10, 3.12, 3.15 on Ubuntu 22.04 and Fedora 42-43, enabling HTTP header injection and code execution, patches now live. https://threatcluster.io/cluster/critical-python-vulnerabilities-affect-multiple-versions-3291ef10

    Post summary

    Critical Python CVEs (CVE‑2026‑1502 and CVE‑2026‑6100) affecting Ubuntu 22.04 and Fedora 42‑43 have been disclosed with patches now available to mitigate HTTP header injection and code execution vulnerabilities.

    0000079
    160 followersView on X
  • Lyiase@lyiase
    General

    Pythonの脆弱性(CVE-2026-6100)まだパッチバージョンが出てないな…。

    Post summary

    The tweet notes that Python CVE‑2026‑6100 remains unpatched but offers no further technical, exploit, or mitigation details.

    00000194
    4.0K followersView on X
  • Lyiase@lyiase
    General

    Python のlzmaのUse After Free脆弱性(CVE-2026-6100)の対象バージョンが分からん、全部か?

    Post summary

    The tweet simply asks which Python lzma versions are affected by CVE-2026-6100, providing no further details beyond the CVE reference.

    00000169
    4.0K followersView on X
  • SystemTek - Technology news website@SystemTek_UK
    Disclosure

    Critical severity vulnerability affecting CPython (CVE-2026-6100) #CPython #CVE20266100 #CyberSecurity https://www.systemtek.co.uk/?p=50686 https://t.co/uj7FsLgy5Y

    Post summary

    A critical vulnerability (CVE‑2026‑6100) affecting CPython has been disclosed.

    0000079
    1.8K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-6100: Use-... Memory-starved Python apps reusing decompressor objects after MemoryError = instant UAF gold mine for RCE hunters. #PythonUAF #MemoryCorruption #RCE. https://zerodaysignal.com/vulnerability/CVE-2026-6100 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2026‑6100, detailing a use‑after‑free vulnerability in Python decompression that could enable remote code execution, but it provides no PoC, patch, or exploitation evidence.

    0000095
    217 followersView on X

Explore more