Medium severityNVD Advisory· Published Jun 4, 2026· Updated Aug 13, 2026
CVE-2026-7774
CVE-2026-7774
Description
tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
21(expand)+ 1 more
- (no CPE)
- (no CPE)
- osv-coords19 versionspkg:apk/chainguard/python-3.10pkg:apk/chainguard/python-3.11pkg:apk/chainguard/python-3.12pkg:apk/chainguard/python-3.13pkg:apk/chainguard/python-3.14pkg:apk/wolfi/python-3.10pkg:apk/wolfi/python-3.11pkg:apk/wolfi/python-3.12pkg:apk/wolfi/python-3.13pkg:apk/wolfi/python-3.14pkg:bitnami/libpythonpkg:bitnami/pythonpkg:bitnami/python-minpkg:rpm/opensuse/python310&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python311&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python312&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python313&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python314&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python315&distro=openSUSE%20Tumbleweed
< 3.10.21-r0+ 18 more
- (no CPE)range: < 3.10.21-r0
- (no CPE)range: < 3.11.15-r9
- (no CPE)range: < 3.12.13-r7
- (no CPE)range: < 3.13.14-r0
- (no CPE)range: < 3.14.6-r1
- (no CPE)range: < 3.10.21-r0
- (no CPE)range: < 3.11.15-r9
- (no CPE)range: < 3.12.13-r7
- (no CPE)range: < 3.13.14-r0
- (no CPE)range: < 3.14.6-r1
- (no CPE)range: < 3.10.21
- (no CPE)range: < 3.10.21
- (no CPE)range: < 3.10.21
- (no CPE)range: < 3.10.20-8.1
- (no CPE)range: < 3.11.15-8.1
- (no CPE)range: < 3.12.13-8.1
- (no CPE)range: < 3.13.14-2.1
- (no CPE)range: < 3.14.6-1.1
- (no CPE)range: < 3.15.0~b2-1.1
Patches
Vulnerability mechanics
References
11- www.openwall.com/lists/oss-security/2026/06/04/9nvd
- github.com/python/cpython/commit/0478bd83d82b255e0f29f613367a59d261e7eaa2nvd
- github.com/python/cpython/commit/0d28f5e46e151718972dfabd91205444d0037b6dnvd
- github.com/python/cpython/commit/10a13bee3c24f9c62b602e696334ff2272a40efcnvd
- github.com/python/cpython/commit/578411982c16f753f4893532510099ef665117danvd
- github.com/python/cpython/commit/5cf47a248c35c375d610b87b2f72fd1ed454b558nvd
- github.com/python/cpython/commit/74cca9a92fb7d653e404843a56b8bdc7b0afdbbfnvd
- github.com/python/cpython/commit/c063191cb7f9170f9565e305f8aa2b79ab2bf609nvd
- github.com/python/cpython/issues/149486nvd
- github.com/python/cpython/pull/149487nvd
- mail.python.org/archives/list/[email protected]/thread/4FU62L2M6RMMHT2QPGQNPEHHUND7CEX5/nvd
News mentions
0No linked articles in our index yet.