workers/extractor.py in Pandora (aka pandora-analysis/pandora) 1.3.0 allows a denial of service when an attacker submits a deeply nested ZIP archive (aka ZIP bomb).
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-22898.json"