PT-2026-51546 · Pypi+1 · Tarfile+1

·

CVE-2026-11940

·

Published

2026-06-23

·

Updated

2026-08-28

CVSS v4.0

7.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Python tarfile (affected versions not specified)
Description A flaw exists in the extractall() function when using the 'data' or 'tar' filters. A specially crafted archive containing a hardlink that references a symlink stored at a deeper path can bypass these filters. The extraction process validates the symlink at its original archived location but recreates it at the shallower path of the hardlink. This allows a relative target to escape the destination directory, enabling a malicious archive to create symlinks that point outside the intended folder, which can lead to unauthorized file reads or writes outside the destination.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Path traversal

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:54268
ALSA-2026:56219
ALSA-2026:58901
ALSA-2026:58902
ALSA-2026:58928
ALSA-2026:58971
ALSA-2026:59009
BIT-LIBPYTHON-2026-11940
BIT-PYTHON-2026-11940
BIT-PYTHON-MIN-2026-11940
CVE-2026-11940
ECHO-4E4C-B37E-F35F
OESA-2026-2919
OESA-2026-2920
OESA-2026-3069
OESA-2026-3072
OPENSUSE-SU-2026:11285-1
OPENSUSE-SU-2026:11286-1
OPENSUSE-SU-2026:11342-1
OPENSUSE-SU-2026:11343-1
OPENSUSE-SU-2026:11427-1
OPENSUSE-SU-2026:11428-1
OPENSUSE-SU-2026:21595-1
PSF-2026-30
RHSA-2026:38018
RHSA-2026:54268
RHSA-2026:54534
RHSA-2026:54554
RHSA-2026:56219
RHSA-2026:58901
RHSA-2026:58902
RHSA-2026:58928
RHSA-2026:58971
RHSA-2026:59009
SUSE-SU-2026:23159-1
SUSE-SU-2026:23191-1
SUSE-SU-2026:23212-1
SUSE-SU-2026:23303-1
SUSE-SU-2026:3245-1
SUSE-SU-2026:3530-1
SUSE-SU-2026:3548-1
SUSE-SU-2026:3560-1
SUSE-SU-2026:3569-1
SUSE-SU-2026:3649-1
SUSE-SU-2026:3855-1

Affected Products

Rocky Linux
Tarfile