CVE-2026-40036 | obsidianforensics unfurl up to 2026.3 Decompression parse_compressed.py parse_compressed allocation of resources (GHSA-h5qv-qjv4-pc5m)
A vulnerability described as problematic has been identified in obsidianforensics unfurl up to 2026.3. Affected by this vulnerability is the function parse_compressed of the file parse_compressed.py of the component Decompression Handler. The manipulation results in allocation of resources.
This vulnerability is identified as CVE-2026-40036. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.