PT-2026-2804 · Guarddog · Guarddog

Dwbruijn

·

Published

2026-01-13

·

Updated

2026-01-21

·

CVE-2026-22870

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GuardDog versions prior to 2.7.1
Description GuardDog, a CLI tool for identifying malicious PyPI packages, contains a flaw in its safe extract() function. This function does not validate the size of decompressed files when handling ZIP archives, such as wheels and eggs. This can lead to a denial of service as attackers can utilize zip bombs – small compressed files that expand to consume excessive disk space, potentially gigabytes from a few megabytes of compressed data.
Recommendations Update to GuardDog version 2.7.1 or later.

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

CVE-2026-22870
GHSA-FFJ4-JQ7M-9G6V

Affected Products

Guarddog