<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 15:40:27 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-68924 — MobSF: Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK Extraction</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-68924</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; MobSF Mobile-Security-Framework-MobSF&lt;/p&gt;
&lt;p&gt;MobSF is a mobile application security testing tool used. Prior to 4.5.1, the unzip function in mobsf/StaticAnalyzer/views/common/shared_func.py logs that an archive member exceeding ZIP_MAX_UNCOMPRESSED_FILE_SIZE is being skipped but does not continue to the next member, so an authenticated user can upload a crafted ZIP or APK whose oversized member is extracted to disk when the aggregate ZIP_MAX_UNCOMPRESSED_TOTAL_SIZE limit has not yet been reached, potentially exhausting disk space and preventing further scans. This issue is fixed in version 4.5.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; MobSF Mobile-Security-Framework-MobSF&lt;/p&gt;
&lt;p&gt;MobSF is a mobile application security testing tool used. Prior to 4.5.1, the unzip function in mobsf/StaticAnalyzer/views/common/shared_func.py logs that an archive member exceeding ZIP_MAX_UNCOMPRESSED_FILE_SIZE is being skipped but does not continue to the next member, so an authenticated user can upload a crafted ZIP or APK whose oversized member is extracted to disk when the aggregate ZIP_MAX_UNCOMPRESSED_TOTAL_SIZE limit has not yet been reached, potentially exhausting disk space and preventing further scans. This issue is fixed in version 4.5.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-68924</guid>
    </item>
    <item>
      <title>GHSA-x768-8642-mmq9 — MobSF Vulnerable to Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK Extraction</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x768-8642-mmq9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: mobsf&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;When extracting uploaded ZIP/APK files, MobSF checks if individual files exceed `ZIP_MAX_UNCOMPRESSED_FILE_SIZE` (400 MB) and logs &amp;#34;Skipping&amp;#34; — but the code lacks a `continue` statement, so extraction proceeds anyway. The log message is misleading; the file is still written to disk.&lt;/p&gt;
&lt;p&gt;### Verified Impact (Code Audit)&lt;/p&gt;
&lt;p&gt;The vulnerable code path in `shared_func.py` lines 153–182:&lt;/p&gt;
&lt;p&gt;```python
# Line 156: Size check
if fileinfo.file_size &amp;gt; settings.ZIP_MAX_UNCOMPRESSED_FILE_SIZE:
    size_mb = fileinfo.file_size / (1024 * 1024)
    msg = (f&amp;#39;File too large ({size_mb:.2f} MB). Skipping &amp;#39;
           f&amp;#39;{sanitize_for_logging(file_path)}&amp;#39;)
    logger.warning(msg)
    # ← BUG: No &amp;#39;continue&amp;#39; here! Execution falls through.&lt;/p&gt;
&lt;p&gt;# Line 161: Total size check (separate)
if total_size &amp;gt; settings.ZIP_MAX_UNCOMPRESSED_TOTAL_SIZE:
    raise Exception(msg)&lt;/p&gt;
&lt;p&gt;# Line 171-178: Permission fixing (only dirs get &amp;#39;continue&amp;#39;)
if fileinfo.is_dir():
    continue
else:
    fileinfo.external_attr = ...&lt;/p&gt;
&lt;p&gt;# Line 182: EXTRACTION ALWAYS HAPPENS FOR FILES
try:
    zipptr.extract(file_path, ext_path)   # ← Runs regardless of size check
```&lt;/p&gt;
&lt;p&gt;The control flow is clear: after the size check logs &amp;#34;Skipping&amp;#34;, no `continue` or `break` is issued. The code proceeds to line 182 which extracts the file unconditionally.&lt;/p&gt;
&lt;p&gt;### Steps to Reproduce&lt;/p&gt;
&lt;p&gt;**1.** Create a ZIP/APK with a file exceeding 400 MB (zeros compress very well):&lt;/p&gt;
&lt;p&gt;```python
#!/usr/bin/env python3
import zipfile, tempfile, os&lt;/p&gt;
&lt;p&gt;output = tempfile.mktemp(suffix=…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: mobsf&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;When extracting uploaded ZIP/APK files, MobSF checks if individual files exceed `ZIP_MAX_UNCOMPRESSED_FILE_SIZE` (400 MB) and logs &amp;#34;Skipping&amp;#34; — but the code lacks a `continue` statement, so extraction proceeds anyway. The log message is misleading; the file is still written to disk.&lt;/p&gt;
&lt;p&gt;### Verified Impact (Code Audit)&lt;/p&gt;
&lt;p&gt;The vulnerable code path in `shared_func.py` lines 153–182:&lt;/p&gt;
&lt;p&gt;```python
# Line 156: Size check
if fileinfo.file_size &amp;gt; settings.ZIP_MAX_UNCOMPRESSED_FILE_SIZE:
    size_mb = fileinfo.file_size / (1024 * 1024)
    msg = (f&amp;#39;File too large ({size_mb:.2f} MB). Skipping &amp;#39;
           f&amp;#39;{sanitize_for_logging(file_path)}&amp;#39;)
    logger.warning(msg)
    # ← BUG: No &amp;#39;continue&amp;#39; here! Execution falls through.&lt;/p&gt;
&lt;p&gt;# Line 161: Total size check (separate)
if total_size &amp;gt; settings.ZIP_MAX_UNCOMPRESSED_TOTAL_SIZE:
    raise Exception(msg)&lt;/p&gt;
&lt;p&gt;# Line 171-178: Permission fixing (only dirs get &amp;#39;continue&amp;#39;)
if fileinfo.is_dir():
    continue
else:
    fileinfo.external_attr = ...&lt;/p&gt;
&lt;p&gt;# Line 182: EXTRACTION ALWAYS HAPPENS FOR FILES
try:
    zipptr.extract(file_path, ext_path)   # ← Runs regardless of size check
```&lt;/p&gt;
&lt;p&gt;The control flow is clear: after the size check logs &amp;#34;Skipping&amp;#34;, no `continue` or `break` is issued. The code proceeds to line 182 which extracts the file unconditionally.&lt;/p&gt;
&lt;p&gt;### Steps to Reproduce&lt;/p&gt;
&lt;p&gt;**1.** Create a ZIP/APK with a file exceeding 400 MB (zeros compress very well):&lt;/p&gt;
&lt;p&gt;```python
#!/usr/bin/env python3
import zipfile, tempfile, os&lt;/p&gt;
&lt;p&gt;output = tempfile.mktemp(suffix=…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x768-8642-mmq9</guid>
    </item>
  </channel>
</rss>
