VDB

CVE-2026-4360

CVE-2026-4360 PUBLISHED CVSS 2 LOW

Reported by PSF · Published June 30, 2026

In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.

Risk Scores

CVSS 4.0
2
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
Python Software FoundationCPython0, 3.11.0, 3.12.0
alpinepython30, 0, 0
chainguardpython-3.100, 0, 0
wolfipython-3.140, 0, 0
chainguardpython-3.130, 0, 0
chainguardpython-3.140, 0, 0
wolfipython-3.120, 0, 0
wolfipython-3.110, 0, 0
wolfipython-3.130, 0, 0
Python Software FoundationCPython0, 0, 0
chainguardpython-3.110, 0, 0
chainguardpython-3.120, 0, 0
wolfipython-3.100, 0, 0

Timeline

  • Jun 30, 2026 CVE Published
  • Jul 1, 2026 EPSS Score
  • Jul 1, 2026 Coalition ESS Score
  • Aug 5, 2026 CVE Updated
  • Aug 7, 2026 EPSS Score
  • Aug 24, 2026 EPSS Score

References

  • vendor-advisory
  • patch
  • issue-tracking
  • patch
  • patch
  • patch
  • patch
  • patch
  • patch
  • patch
Open in Interactive Console →
$ Console Community · 100/wk Open console ›