CVE-2026-11940

Aliases:RHSA-2026:54268UBUNTU-CVE-2026-11940DEBIAN-CVE-2026-11940openSUSE-SU-2026:11343-1ALPINE-CVE-2026-11940RHSA-2026:56219RHSA-2026:58902RHSA-2026:58971RHSA-2026:59009RHSA-2026:58901RHSA-2026:58928RHSA-2026:62809RHSA-2026:63024RHSA-2026:63117CGA-2877-fmjf-8j5qCGA-4fpg-c7fm-99ghCGA-5363-9r7r-rr55CGA-cr9q-h4v8-hfgpCGA-p58r-m62v-qgvqCGA-p86c-g5pg-rvpwCGA-qmm2-954x-xmxrCGA-r3fp-2qp4-4grgCGA-rqc4-gw8x-6hw7CGA-w3m6-c9vj-wm85RHSA-2026:64806RHSA-2026:64816
Awaiting Analysis
Published: 23 Jun 2026, 16:04
Last modified:13 Aug 2026, 00:28

Vulnerability Summary

Overall Risk (default)
medium
31/100
CVSS Score
7.8 HIGH
v4.0 (cve.org)
EPSS Score
0.75% LOW
1% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

23 Jun 2026, 16:04
Published
Vulnerability first disclosed
13 Aug 2026, 00:28
Last Modified
Vulnerability information updated

Description

tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a deeper name than the hardlink itself. The extraction fallback validated the symlink at it's archived location but recreated it at the hardlink's shallower path, letting a relative target the filter judged contained escape the destination directory. This allowed a malicious tar archive to create a symlink pointing outside the destination, enabling out-of-destination file reads or writes. This was an incomplete fix of CVE-2025-4330.

CVSS Metrics

  • v4.0HIGHScore: 7.8CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N
  • v4.0HIGHScore: 7.8CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • v3.1HIGHScore: 7.3CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

EPSS Trends

Current EPSS score: 0.75% Percentile: 53%

Techniques & Countermeasures

  • CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

  • CWE-59Improper Link Resolution Before File Access ('Link Following')

    The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Affected Systems

  • alpinepython3

    < 3.12.14-r0 | < 3.12.14-r0 | < 3.12.14-r0 | < 3.14.7-r0

  • chainguardpython-3.10

    < 3.10.20-r10

  • chainguardpython-3.11

    < 3.11.15-r8

  • chainguardpython-3.12

    < 3.12.13-r10

  • chainguardpython-3.13

    < 3.13.14-r2

  • chainguardpython-3.14

    < 3.14.6-r3

  • wolfipython-3.10

    < 3.10.20-r10

  • wolfipython-3.11

    < 3.11.15-r8

  • wolfipython-3.12

    < 3.12.13-r10

  • wolfipython-3.13

    < 3.13.14-r2

  • wolfipython-3.14

    < 3.14.6-r3

  • debianpypy3

    all | all

  • debianpython2.7

    all

  • debianpython3.11

    all

  • debianpython3.13

    all | all | < 3.13.5-2+deb13u5 | < 3.13.15-1

  • debianpython3.14

    all | < 3.14.7-1

  • debianpython3.9

    all

  • ubuntupypy3

    all | all | all | all | all

  • ubuntupython2.7

    all

  • ubuntupython3.10

    all

  • ubuntupython3.11

    all | all

  • ubuntupython3.12

    all

  • ubuntupython3.13

    all

  • ubuntupython3.14

    all | all

  • ubuntupython3.4

    all

  • ubuntupython3.5

    all

  • ubuntupython3.6

    all

  • ubuntupython3.7

    all

  • ubuntupython3.8

    all

  • ubuntupython3.9

    all

  • python software foundationcpython

    < 3.16.0 | < 3.15.0 | < 3.13.15 | < 3.10.21 | ≥ 3.11.0, < 3.11.16 | ≥ 3.12.0, < 3.12.14 | ≥ 3.13.0, < 3.13.15 | ≥ 3.14.0, < 3.14.7 | ≥ 3.15.0a1, < 3.15.0b4

  • opensusepython314&distro=openSUSE Tumbleweed

    < 3.14.6-2.1

  • redhatplatform-python

    < 0:3.6.8-78.el8_10 | < 0:3.6.8-78.el8_10 | < 0:3.6.8-51.el8_8.17 | < 0:3.6.8-51.el8_8.17 | < 0:3.6.8-47.el8_6.15 | < 0:3.6.8-47.el8_6.15

  • redhatplatform-python-debug

    < 0:3.6.8-78.el8_10 | < 0:3.6.8-51.el8_8.17 | < 0:3.6.8-47.el8_6.15

  • redhatplatform-python-devel

    < 0:3.6.8-78.el8_10 | < 0:3.6.8-51.el8_8.17 | < 0:3.6.8-47.el8_6.15

  • redhatpython-unversioned-command

    < 0:3.9.25-7.el9_8.3 | < 0:3.12.14-1.el10_2 | < 0:3.12.9-2.el10_0.11

  • redhatpython3

    < 0:3.9.25-7.el9_8.3 | < 0:3.9.25-7.el9_8.3 | < 0:3.6.8-78.el8_10 | < 0:3.12.14-1.el10_2 | < 0:3.12.9-2.el10_0.11 | < 0:3.6.8-51.el8_8.17 | < 0:3.6.8-47.el8_6.15

  • redhatpython3-debug

    < 0:3.9.25-7.el9_8.3 | < 0:3.12.14-1.el10_2 | < 0:3.12.9-2.el10_0.11

  • redhatpython3-debuginfo

    < 0:3.6.8-78.el8_10 | < 0:3.6.8-78.el8_10 | < 0:3.6.8-51.el8_8.17 | < 0:3.6.8-51.el8_8.17 | < 0:3.6.8-47.el8_6.15 | < 0:3.6.8-47.el8_6.15

  • redhatpython3-debugsource

    < 0:3.6.8-78.el8_10 | < 0:3.6.8-78.el8_10 | < 0:3.6.8-51.el8_8.17 | < 0:3.6.8-51.el8_8.17 | < 0:3.6.8-47.el8_6.15 | < 0:3.6.8-47.el8_6.15

  • redhatpython3-devel

    < 0:3.9.25-7.el9_8.3 | < 0:3.12.14-1.el10_2 | < 0:3.12.9-2.el10_0.11

  • redhatpython3-idle

    < 0:3.9.25-7.el9_8.3 | < 0:3.6.8-78.el8_10 | < 0:3.12.14-1.el10_2 | < 0:3.12.9-2.el10_0.11 | < 0:3.6.8-51.el8_8.17 | < 0:3.6.8-47.el8_6.15

  • redhatpython3-libs

    < 0:3.9.25-7.el9_8.3 | < 0:3.6.8-78.el8_10 | < 0:3.12.14-1.el10_2 | < 0:3.12.9-2.el10_0.11 | < 0:3.6.8-51.el8_8.17 | < 0:3.6.8-47.el8_6.15

  • redhatpython3-test

    < 0:3.9.25-7.el9_8.3 | < 0:3.6.8-78.el8_10 | < 0:3.6.8-78.el8_10 | < 0:3.12.14-1.el10_2 | < 0:3.12.9-2.el10_0.11 | < 0:3.6.8-51.el8_8.17 | < 0:3.6.8-51.el8_8.17 | < 0:3.6.8-47.el8_6.15 | < 0:3.6.8-47.el8_6.15

  • redhatpython3-tkinter

    < 0:3.9.25-7.el9_8.3 | < 0:3.9.25-7.el9_8.3 | < 0:3.6.8-78.el8_10 | < 0:3.12.14-1.el10_2 | < 0:3.12.9-2.el10_0.11 | < 0:3.6.8-51.el8_8.17 | < 0:3.6.8-47.el8_6.15

  • redhatpython3.12

    < 0:3.12.14-1.el10_2 | < 0:3.12.14-1.el8_10 | < 0:3.12.14-1.el8_10 | < 0:3.12.14-1.el9_8 | < 0:3.12.14-1.el9_8 | < 0:3.12.1-4.el9_4.15 | < 0:3.12.9-2.el10_0.11 | < 0:3.12.9-1.el9_6.10 | < 0:3.12.9-1.el9_6.10

  • redhatpython3.12-debug

    < 0:3.12.14-1.el8_10 | < 0:3.12.14-1.el9_8 | < 0:3.12.9-1.el9_6.10

  • redhatpython3.12-debuginfo

    < 0:3.12.14-1.el10_2 | < 0:3.12.14-1.el8_10 | < 0:3.12.14-1.el8_10 | < 0:3.12.14-1.el9_8 | < 0:3.12.14-1.el9_8 | < 0:3.12.1-4.el9_4.15 | < 0:3.12.9-2.el10_0.11 | < 0:3.12.9-1.el9_6.10 | < 0:3.12.9-1.el9_6.10

  • redhatpython3.12-debugsource

    < 0:3.12.14-1.el10_2 | < 0:3.12.14-1.el8_10 | < 0:3.12.14-1.el8_10 | < 0:3.12.14-1.el9_8 | < 0:3.12.14-1.el9_8 | < 0:3.12.1-4.el9_4.15 | < 0:3.12.9-2.el10_0.11 | < 0:3.12.9-1.el9_6.10 | < 0:3.12.9-1.el9_6.10

  • redhatpython3.12-devel

    < 0:3.12.14-1.el8_10 | < 0:3.12.14-1.el9_8 | < 0:3.12.1-4.el9_4.15 | < 0:3.12.9-1.el9_6.10

Showing first 50 affected entries in server-rendered view.

References (45)