5.7
CVE-2026-87910
- EPSS 0.42%
- Veröffentlicht 11.09.2026 17:27:04
- Zuletzt bearbeitet 03.10.2026 01:17:25
- Erkennungen
tarfile hardlink fallback ignores custom extraction filter rejection via None
When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerPython Software Foundation
≫
Produkt
CPython
Default Statusunaffected
Version
0
Version <
3.10.22
Status
affected
Version
3.11.0
Version <
3.11.17
Status
affected
Version
3.12.0
Version <
3.12.15
Status
affected
Version
3.13.0
Version <
3.13.16
Status
affected
Version
3.15.0a1
Version <
3.15.0rc3
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.42% | 0.358 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| cna@python.org | 5.7 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CWE-59 Improper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
https://mail.python.org/archives/list/security-announce@python.org/thread/57TBTLL2W6APMZR3A25B2YV7GL3EPTDJ/
https://github.com/python/cpython/pull/157266
https://github.com/python/cpython/issues/157265
http://www.openwall.com/lists/oss-security/2026/09/11/8
https://github.com/python/cpython/commit/d9565e54b1fc6d63c5be9afd58114499128fa57b
https://github.com/python/cpython/commit/fb2f0bbc3b35264f09cc2cb2934b7987527a6bc2
https://github.com/python/cpython/commit/9c17bace90f88dfba6d0e2fe23c8e7ae35f83955
https://github.com/python/cpython/commit/764fd0af8d9e19d3684a58d2e58bf770f0605036
https://github.com/python/cpython/commit/2eb0c2f1dc71847731b6ab30aebefd058d482a7f
https://github.com/python/cpython/commit/c1f106d240c4ffcb3608ed0a20e8aba6c865f6d3
https://github.com/python/cpython/commit/3105a3498aaf681ce128cf5baf83c2e5574267c5
https://github.com/python/cpython/commit/a4919937a4e1e69a0d178909c6f20557eca5d1d0