CVE-2026-11940

Summary

tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a deeper name than the hardlink itself.  The extraction fallback validated the symlink at it's archived location but recreated it at the hardlink's shallower path, letting a relative target the filter judged contained escape the destination directory.  This allowed a malicious tar archive to create a symlink pointing outside the destination, enabling out-of-destination file reads or writes. This was an incomplete fix of CVE-2025-4330.

Affected Software

VendorProductVersion RangeStatus
Python Software FoundationCPython0 < 3.10.21affected
Python Software FoundationCPython3.11.0 < 3.11.16affected
Python Software FoundationCPython3.12.0 < 3.12.14affected
Python Software FoundationCPython3.13.0 < 3.13.15affected
Python Software FoundationCPython3.14.0 < 3.14.7affected
Python Software FoundationCPython3.15.0a1 < 3.15.0b4affected

Weaknesses

  • CWE-22: CWE-22
  • CWE-59: CWE-59

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References