<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T15:52:52.388788+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-68924</id>
    <title>CVE-2026-68924 — MobSF: Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK Extraction</title>
    <updated>2026-10-03T15:52:52.390777+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> MobSF Mobile-Security-Framework-MobSF</p>
<p>MobSF is a mobile application security testing tool used. Prior to 4.5.1, the unzip function in mobsf/StaticAnalyzer/views/common/shared_func.py logs that an archive member exceeding ZIP_MAX_UNCOMPRESSED_FILE_SIZE is being skipped but does not continue to the next member, so an authenticated user can upload a crafted ZIP or APK whose oversized member is extracted to disk when the aggregate ZIP_MAX_UNCOMPRESSED_TOTAL_SIZE limit has not yet been reached, potentially exhausting disk space and preventing further scans. This issue is fixed in version 4.5.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-68924"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-x768-8642-mmq9</id>
    <title>GHSA-x768-8642-mmq9 — MobSF Vulnerable to Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK Extraction</title>
    <updated>2026-10-03T15:52:52.390851+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: mobsf</p>
<p>### Summary</p>
<p>When extracting uploaded ZIP/APK files, MobSF checks if individual files exceed `ZIP_MAX_UNCOMPRESSED_FILE_SIZE` (400 MB) and logs "Skipping" — but the code lacks a `continue` statement, so extraction proceeds anyway. The log message is misleading; the file is still written to disk.</p>
<p>### Verified Impact (Code Audit)</p>
<p>The vulnerable code path in `shared_func.py` lines 153–182:</p>
<p>```python
# Line 156: Size check
if fileinfo.file_size &gt; settings.ZIP_MAX_UNCOMPRESSED_FILE_SIZE:
    size_mb = fileinfo.file_size / (1024 * 1024)
    msg = (f'File too large ({size_mb:.2f} MB). Skipping '
           f'{sanitize_for_logging(file_path)}')
    logger.warning(msg)
    # ← BUG: No 'continue' here! Execution falls through.</p>
<p># Line 161: Total size check (separate)
if total_size &gt; settings.ZIP_MAX_UNCOMPRESSED_TOTAL_SIZE:
    raise Exception(msg)</p>
<p># Line 171-178: Permission fixing (only dirs get 'continue')
if fileinfo.is_dir():
    continue
else:
    fileinfo.external_attr = ...</p>
<p># Line 182: EXTRACTION ALWAYS HAPPENS FOR FILES
try:
    zipptr.extract(file_path, ext_path)   # ← Runs regardless of size check
```</p>
<p>The control flow is clear: after the size check logs "Skipping", no `continue` or `break` is issued. The code proceeds to line 182 which extracts the file unconditionally.</p>
<p>### Steps to Reproduce</p>
<p>**1.** Create a ZIP/APK with a file exceeding 400 MB (zeros compress very well):</p>
<p>```python
#!/usr/bin/env python3
import zipfile, tempfile, os</p>
<p>output = tempfile.mktemp(suffix=…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-x768-8642-mmq9"/>
  </entry>
</feed>
