VDB
CVE-2026-4360
CVE-2026-4360
PUBLISHED
CVSS 2 LOW
Reported by PSF · Published June 30, 2026
In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.
Risk Scores
CVSS 4.0
2
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Python Software Foundation | CPython | 0, 3.11.0, 3.12.0 |
| alpine | python3 | 0, 0, 0 |
| chainguard | python-3.10 | 0, 0, 0 |
| wolfi | python-3.14 | 0, 0, 0 |
| chainguard | python-3.13 | 0, 0, 0 |
| chainguard | python-3.14 | 0, 0, 0 |
| wolfi | python-3.12 | 0, 0, 0 |
| wolfi | python-3.11 | 0, 0, 0 |
| wolfi | python-3.13 | 0, 0, 0 |
| Python Software Foundation | CPython | 0, 0, 0 |
| chainguard | python-3.11 | 0, 0, 0 |
| chainguard | python-3.12 | 0, 0, 0 |
| wolfi | python-3.10 | 0, 0, 0 |
Timeline
- Jun 30, 2026 CVE Published
- Jul 1, 2026 EPSS Score
- Jul 1, 2026 Coalition ESS Score
- Aug 5, 2026 CVE Updated
- Aug 7, 2026 EPSS Score
- Aug 24, 2026 EPSS Score