CVE-2026-4360
Tarfile.extract() doesn't fully respect filter parameter
Vexday Risk Score
8Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 2EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
30 Jun 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Affected products
Python Software Foundation · CPythonWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://github.com/python/cpython/commit/5e0ef3f1afe892e4f64eb83368db57ac4c40cba0https://github.com/python/cpython/commit/7b57e8d51446297b8c7c482d224bc5f1938e4301https://github.com/python/cpython/commit/7ccdbaba2c54250a70d7f25632152df7655a5e0ahttps://github.com/python/cpython/commit/eee3ddf0ca10283cc7fea724aae9cd8665f8d15ehttps://github.com/python/cpython/issues/151987https://github.com/python/cpython/pull/151988https://mail.python.org/archives/list/security-announce@python.org/thread/TWZW2PC2AZOV6FENIHFSRC63OM7MBGSB/