CVE-2026-11972

Aliases:RHSA-2026:35806RHSA-2026:35807RHSA-2026:35812RHSA-2026:35813UBUNTU-CVE-2026-11972DEBIAN-CVE-2026-11972ALPINE-CVE-2026-11972CGA-29x2-h669-f2hxCGA-3g7p-9qvq-83m3CGA-498m-q8g7-j6w8CGA-55jf-rmq5-v8vmCGA-c8vx-jqg6-gc5hCGA-hw8r-qxr7-v53xCGA-m586-cxjf-9w4pCGA-w287-q9rf-58j3CGA-w2cw-v85q-v9prCGA-wphf-rqvv-m5vj
Awaiting Analysis
Published: 23 Jun 2026, 22:02
Last modified:13 Aug 2026, 00:28

Vulnerability Summary

Overall Risk (default)
medium
33/100
CVSS Score
8.2 HIGH
v4.0 (cve.org)
EPSS Score
0.45% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

23 Jun 2026, 22:02
Published
Vulnerability first disclosed
13 Aug 2026, 00:28
Last Modified
Vulnerability information updated

Description

When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.

CVSS Metrics

  • v4.0HIGHScore: 8.2CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  • v4.0HIGHScore: 8.2CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • v3.1MEDIUMScore: 6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.45% Percentile: 38%

Techniques & Countermeasures

  • CWE-252Unchecked Return Value

    The product does not check the return value from a method or function, which can prevent it from detecting unexpected states and conditions.

  • CWE-606Unchecked Input for Loop Condition

    The product does not properly check inputs that are used for loop conditions, potentially leading to a denial of service or other consequences because of excessive looping.

  • CWE-770Allocation of Resources Without Limits or Throttling

    The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Affected Systems

  • alpinepython3

    < 3.12.14-r0 | < 3.12.14-r0 | < 3.12.14-r0 | < 3.14.7-r0

  • chainguardpython-3.10

    < 3.10.20-r10

  • chainguardpython-3.11

    < 3.11.15-r8

  • chainguardpython-3.12

    < 3.12.13-r10

  • chainguardpython-3.13

    < 3.13.14-r2

  • chainguardpython-3.14

    < 3.14.6-r3

  • wolfipython-3.10

    < 3.10.20-r10

  • wolfipython-3.11

    < 3.11.15-r8

  • wolfipython-3.12

    < 3.12.13-r10

  • wolfipython-3.13

    < 3.13.14-r2

  • wolfipython-3.14

    < 3.14.6-r3

  • debianpypy3

    all | all | all | all

  • debianpython2.7

    all

  • debianpython3.11

    all

  • debianpython3.13

    all | all | < 3.13.5-2+deb13u5 | < 3.13.15-1

  • debianpython3.14

    all | < 3.14.7-1

  • debianpython3.9

    all

  • ubuntupython2.7

    all

  • ubuntupython3.10

    all

  • ubuntupython3.11

    all | all

  • ubuntupython3.12

    all

  • ubuntupython3.13

    all

  • ubuntupython3.14

    all | all

  • ubuntupython3.4

    all

  • ubuntupython3.5

    all

  • ubuntupython3.6

    all

  • ubuntupython3.7

    all

  • ubuntupython3.8

    all

  • ubuntupython3.9

    all

  • python software foundationcpython

    < 3.16.0 | < 3.15.0 | < 3.13.15 | < 3.10.21 | ≥ 3.11.0, < 3.11.16 | ≥ 3.12.0, < 3.12.14 | ≥ 3.13.0, < 3.13.15 | ≥ 3.14.0, < 3.14.7 | ≥ 3.15.0a1, < 3.15.0b4

  • redhatpython3.11

    < 0:3.11.15-4.4.hum1

  • redhatpython3.12

    < 0:3.12.13-3.3.hum1

  • redhatpython3.13

    < 0:3.13.14-1.2.hum1

  • redhatpython3.14

    < 0:3.14.6-1.2.hum1

References (29)