GHSA-8jvr-397x-xqh9 · Severity: high — bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught...
bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data.
Conclusion & alert: CVE-2026-9669 is rated Moderate Risk (43.3/100): CVSS High severity, with low exploitation likelihood (EPSS 0.38%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.07% | 0.38% | +0.31% |
| 2 | 2026-06-14 | 0.04% | 0.07% | +0.02% |
| 3 | 2026-06-09 | — | 0.04% | — |
Full EPSS history (3 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.2 | 4.0 | HIGH |
|
— | — | [email protected] |
GHSA-8jvr-397x-xqh9 · Severity: high — bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught...
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2026-9669 not yet assigned priority: Debian including 4 source packages (python3.11, python3.13, python3.14, python3.9), 7 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 4, open 3. | https://security-tracker.debian.org/tracker/CVE-2026-9669 |
suse
|
medium | CVE-2026-9669 severity moderate: SUSE including 18 source package names (python, python-32bit, …), 115 product×package rows across 22 product lines (SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS, SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS, … (22 product lines)): Known Not Affected 115. | https://www.suse.com/security/cve/CVE-2026-9669/ |
ubuntu
|
medium | CVE-2026-9669 medium priority: Ubuntu including 12 source packages (python2.7, python3.10, …), 72 status rows across 9 suites (bionic, focal, jammy, noble, questing, resolute, trusty, upstream, xenial): DNE 41, needs-triage 31. | https://ubuntu.com/security/CVE-2026-9669 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||