Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-6100

34
FAUCET Score

OVERVIEW CVE-2026-6100 is a use-after-free vulnerability in Python's compression modules (lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile) that occurs when memory allocation fails during decompression and the decompressor instance is subsequently reused. The vulnerability manifests when a MemoryError is raised in a memory-constrained environment and the same decompressor object is leveraged for additional decompression operations, leaving a dangling pointer that can be exploited. The vulnerability does not affect one-shot decompression helper functions or instances that are not reused after error conditions. SEVERITY While a complete CVSS score is not available, the vulnerability is characterized as a use-after-free condition that is theoretically exploitable. The attack requires specific conditions: an application must reuse decompressor instances across multiple calls, encounter a MemoryError during decompression, and then attempt further decompression operations. The EPSS score of 0.0015 indicates an exceptionally low probability of exploitation in the wild, placing it in the lowest percentile of vulnerabilities. The FAUCET Risk Score of 53/100 suggests moderate concern from a risk management perspective. EXPLOITATION STATUS There is no evidence of active exploitation. The vulnerability has not been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, and it is not currently listed on any vulnerability hot list. Exploitation requires highly specific application behavior (reusing decompressor instances after encountering memory errors), which is not a common coding pattern, significantly limiting the practical attack surface in real-world deployments.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, < 3.13.14CPE match
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

9.1CRITICAL

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
HIGH
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.58%
Probability of exploitation in next 30 days
EPSS Percentile
44.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0058 is in the 16th percentile among its peer group of 8,918 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

ubuntupatch availablevia ubuntu_usn
Product: python3.10 (jammy)Fixed in: 3.10.12-1~22.04.16
ubuntupatch availablevia ubuntu_usn
Product: python3.12 (noble)Fixed in: 3.12.3-1ubuntu0.15
ubuntupatch availablevia ubuntu_usn
Product: python3.14 (resolute)Fixed in: 3.14.4-1ubuntu0.1

Vendor Advisories (2)

ubuntuUSN-8509-1

Python vulnerabilities

Jul 6, 2026
microsoft2026-Apr/CVE-2026-6100Important

Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure

Apr 14, 2026

References

access.redhat.com / errata/RHSA-2026:10117
access.redhat.com / errata/RHSA-2026:10140
access.redhat.com / errata/RHSA-2026:10141
access.redhat.com / errata/RHSA-2026:10711
access.redhat.com / errata/RHSA-2026:10745
access.redhat.com / errata/RHSA-2026:10774
access.redhat.com / errata/RHSA-2026:10949
access.redhat.com / errata/RHSA-2026:10950
access.redhat.com / errata/RHSA-2026:11062
access.redhat.com / errata/RHSA-2026:11077
access.redhat.com / errata/RHSA-2026:11768
access.redhat.com / errata/RHSA-2026:13692
access.redhat.com / errata/RHSA-2026:13812
access.redhat.com / errata/RHSA-2026:14652
access.redhat.com / errata/RHSA-2026:14653
access.redhat.com / errata/RHSA-2026:14656
access.redhat.com / errata/RHSA-2026:16699
access.redhat.com / errata/RHSA-2026:17525
access.redhat.com / errata/RHSA-2026:17619
access.redhat.com / errata/RHSA-2026:19019
access.redhat.com / errata/RHSA-2026:19064
access.redhat.com / errata/RHSA-2026:19175
access.redhat.com / errata/RHSA-2026:19176
access.redhat.com / errata/RHSA-2026:19177
access.redhat.com / errata/RHSA-2026:19216
access.redhat.com / errata/RHSA-2026:19549
access.redhat.com / errata/RHSA-2026:19570
access.redhat.com / errata/RHSA-2026:19571
access.redhat.com / errata/RHSA-2026:19576
access.redhat.com / errata/RHSA-2026:19590
access.redhat.com / errata/RHSA-2026:21275
access.redhat.com / errata/RHSA-2026:21682
access.redhat.com / errata/RHSA-2026:25096
access.redhat.com / errata/RHSA-2026:26187
access.redhat.com / errata/RHSA-2026:30078
access.redhat.com / errata/RHSA-2026:30087
access.redhat.com / errata/RHSA-2026:30088
access.redhat.com / errata/RHSA-2026:30089
access.redhat.com / errata/RHSA-2026:8822
access.redhat.com / errata/RHSA-2026:8824
access.redhat.com / errata/RHSA-2026:9228
access.redhat.com / security/cve/CVE-2026-6100
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-6100.json
openwall.com / lists/oss-security/2026/04/13/10
github.com / python/cpython/commit/47128e64f98c3a20271138a98c2922bea2a3ee0e
github.com / python/cpython/commit/6a5f79c8d7bbf22b083b240910c7a8781a59437d
github.com / python/cpython/commit/8fc66aef6d7b3ae58f43f5c66f9366cc8cbbfcd2
github.com / python/cpython/commit/c3cf71c3366fe49acb776a639405c0eea6169c20
github.com / python/cpython/commit/e20c6c9667c99ecaab96e1a2b3767082841ffc8b
github.com / python/cpython/issues/148395
github.com / python/cpython/pull/148396
mail.python.org / archives/list/[email protected]/thread/HTWB2Z6KT5QQX4RYEZAFININDHNOSIF3