CodeChecker's massStoreRun processing path performs one-shot decompression of attacker-controlled, Base64-encoded zlib data without enforcing a maximum decompressed size.
An authenticated user with permission to store analysis runs can submit a highly compressed payload that expands to a significantly larger byte sequence. Because the entire decompressed output is materialized in memory before being written to a temporary file, a sufficiently large payload may exhaust process or host memory and consume substantial disk space, resulting in denial of service.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/58xxx/CVE-2026-58107.json",
"cwe_ids": [
"CWE-409",
"CWE-770"
],
"cna_assigner": "ERIC"
}[
{
"id": "CVE-2026-58107-d0b42bb4",
"target": {
"function": "getDefaultArguments",
"file": "analyzer/tools/build-logger/src/ldlogger-tool-gcc.c"
},
"deprecated": false,
"digest": {
"function_hash": "58253484336060859784604701737763940436",
"length": 965.0
},
"signature_version": "v1",
"source": "https://github.com/ericsson/codechecker/commit/cc251975c3dcd74f738ce3b80ae6e72b444e67a6",
"signature_type": "Function"
},
{
"id": "CVE-2026-58107-e5e44443",
"target": {
"file": "analyzer/tools/build-logger/src/ldlogger-tool-gcc.c"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"176050040485224728587349282730126651100",
"267609529918766960889900993245124430378",
"6749681309481896638497142464294374583",
"339116569381575010668585316151724078479"
]
},
"signature_version": "v1",
"source": "https://github.com/ericsson/codechecker/commit/cc251975c3dcd74f738ce3b80ae6e72b444e67a6",
"signature_type": "Line"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-58107.json"
"2026-08-30T08:17:30Z"