8.7

CVE-2026-41140

Poetry: Path traversal in tar extraction on Python 3.10.0 - 3.10.12 and 3.11.0 - 3.11.4

Poetry is a dependency manager for Python. Prior to 2.3.4, the extractall() function in src/poetry/utils/helpers.py:410-426 extracts sdist tarballs without path traversal protection on Python versions where tarfile.data_filter is unavailable. Considering only Python versions which are still supported by Poetry, these are 3.10.0 - 3.10.12 and 3.11.0 - 3.11.4. This vulnerability is fixed in 2.3.4.
Daten sind bereitgestellt durch das CVE Programm von Authorized Data Publishers (ADP) (Unstrukturiert)
HerstellerRed Hat
≫
Produkt Red Hat Ansible Automation Platform 2.6
Default Statusaffected
Version 1779761061
Version < *
Status unaffected
HerstellerRed Hat
≫
Produkt Red Hat Ansible Automation Platform 2.6
Default Statusaffected
Version 1780102732
Version < *
Status unaffected
HerstellerRed Hat
≫
Produkt Red Hat Ansible Automation Platform 2
Default Statusaffected
HerstellerRed Hat
≫
Produkt Red Hat Ansible Automation Platform 2
Default Statusunaffected
HerstellerRed Hat
≫
Produkt Red Hat OpenShift AI (RHOAI)
Default Statusunaffected
HerstellerRed Hat
≫
Produkt Red Hat OpenShift AI (RHOAI)
Default Statusunaffected
HerstellerRed Hat
≫
Produkt Red Hat OpenShift AI (RHOAI)
Default Statusunaffected
HerstellerRed Hat
≫
Produkt Red Hat OpenShift AI (RHOAI)
Default Statusunaffected
HerstellerRed Hat
≫
Produkt Red Hat OpenShift Container Platform 4
Default Statusaffected
HerstellerRed Hat
≫
Produkt Red Hat Satellite 6
Default Statusunaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.29% 0.21
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 0.6 0 0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
0b0ca135-0b70-47e7-9f44-1890c2a1c46c 8.7 2.3 5.8
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

https://bugzilla.redhat.com/show_bug.cgi?id=2461604
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41140.json
https://access.redhat.com/errata/RHSA-2026:24866
https://github.com/python-poetry/poetry/security/advisories/GHSA-73h3-mf4w-8647
https://access.redhat.com/security/cve/CVE-2026-41140