7.8

CVE-2026-11940

tarfile extraction filter bypass allows escaping the destination directory

tarfile.extractall() with the 'data' or 'tar'
 filter could be bypassed by a crafted archive where a hardlink 
references a symlink stored at a deeper name than the hardlink itself.  
The extraction fallback validated the symlink at it's archived location 
but recreated it at the hardlink's shallower
path, letting a relative
 target the filter judged contained escape the destination directory.  
This allowed a malicious tar archive to create a symlink pointing 
outside the destination, enabling out-of-destination file reads or 
writes. This was an incomplete fix of CVE-2025-4330.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerPython Software Foundation
≫
Produkt CPython
Default Statusunaffected
Version 0
Version < 3.10.21
Status affected
Version 3.11.0
Version < 3.11.16
Status affected
Version 3.12.0
Version < 3.12.14
Status affected
Version 3.13.0
Version < 3.13.15
Status affected
Version 3.14.0
Version < 3.14.7
Status affected
Version 3.15.0a1
Version < 3.15.0b4
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.75% 0.516
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
cna@python.org 7.8 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

CWE-59 Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

https://github.com/python/cpython/pull/151559
https://github.com/python/cpython/issues/151558
https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f
https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df
https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde
https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c
https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9
https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/
https://github.com/python/cpython/commit/e5fdbd8d5aa923bd9111b112ea73bd6ec7c47877
https://github.com/python/cpython/commit/0f852b3f07dd8e71e40326a51c02afbf16a42cc5