CVE-2026-7774

Aliases:DEBIAN-CVE-2026-7774ALPINE-CVE-2026-7774SUSE-SU-2026:3851-1CGA-2hr7-vw6r-h3gvCGA-56jr-xmq9-2hhwCGA-9mgv-r5gf-82qfCGA-9p8r-m77c-89wxCGA-9rgf-jgjj-f22vCGA-h6v3-9x58-7r4wCGA-jm2h-44cv-mmv5CGA-rjp8-h8gw-84wjCGA-wr5v-vw9q-j67vCGA-x64c-h9vj-q7fc
Awaiting Analysis
Published: 04 Jun 2026, 14:21
Last modified:13 Aug 2026, 00:26

Vulnerability Summary

Overall Risk (default)
medium
28/100
CVSS Score
6.9 MEDIUM
v4.0 (cve.org)
EPSS Score
0.6% LOW
1% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

04 Jun 2026, 14:21
Published
Vulnerability first disclosed
13 Aug 2026, 00:26
Last Modified
Vulnerability information updated

Description

tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.

CVSS Metrics

  • v4.0MEDIUMScore: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
  • v4.0MEDIUMScore: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

EPSS Trends

Current EPSS score: 0.60% Percentile: 47%

Techniques & Countermeasures

  • CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Affected Systems

  • alpinepython3

    < 3.14.7-r0

  • chainguardpython-3.10

    < 3.10.21-r0

  • chainguardpython-3.11

    < 3.11.15-r9

  • chainguardpython-3.12

    < 3.12.13-r7

  • chainguardpython-3.13

    < 3.13.14-r0

  • chainguardpython-3.14

    < 3.14.6-r1

  • wolfipython-3.10

    < 3.10.21-r0

  • wolfipython-3.11

    < 3.11.15-r9

  • wolfipython-3.12

    < 3.12.13-r7

  • wolfipython-3.13

    < 3.13.14-r0

  • wolfipython-3.14

    < 3.14.6-r1

  • debianpypy3

    all | all

  • debianpython3.13

    < 3.13.5-2+deb13u3 | < 3.13.14-1

  • debianpython3.14

    < 3.14.6-1

  • python software foundationcpython

    < 3.15.0 | < 3.13.14 | < 3.10.21 | ≥ 3.11.0, < 3.11.16 | ≥ 3.12.0, < 3.12.14 | ≥ 3.13.0, < 3.13.14 | ≥ 3.14.0, < 3.14.6 | ≥ 3.15.0a1, < 3.15.0b2

  • susepython310-core&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS

    < 3.10.20-150400.4.118.1

  • susepython310-core&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS

    < 3.10.20-150400.4.118.1

  • susepython310-core&distro=SUSE Linux Enterprise Server 15 SP4-LTSS

    < 3.10.20-150400.4.118.1

  • susepython310-core&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP4

    < 3.10.20-150400.4.118.1

  • susepython310&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS

    < 3.10.20-150400.4.118.1

  • susepython310&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS

    < 3.10.20-150400.4.118.1

  • susepython310&distro=SUSE Linux Enterprise Server 15 SP4-LTSS

    < 3.10.20-150400.4.118.1

  • susepython310&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP4

    < 3.10.20-150400.4.118.1

References (19)