CVE-2026-3479Path Traversal in Software Foundation Cpython

CWE-22Path Traversal21 documents9 sources
Severity
0.0N/ANVD
EPSS
0.0%
top 97.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 18
Latest updateMar 19

Description

DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model. pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.

CVSS vector

CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Packages1 packages

CVEListV5python_software_foundation/cpython3.14.03.14.4+2

🔴Vulnerability Details

4
OSV
CVE-2026-3479: DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil2026-03-18
CVEList
pkgutil.get_data() does not enforce documented restrictions2026-03-18
GHSA
GHSA-43rw-359f-4h89: pkgutil2026-03-18
OSV
CVE-2026-3479: pkgutil2026-03-18

📋Vendor Advisories

3
Red Hat
python: Python pkgutil.get_data(): Path Traversal via improper resource argument validation2026-03-18
Microsoft
pkgutil.get_data() does not enforce documented restrictions2026-03-10
Debian
CVE-2026-3479: pypy3 - DISPUTED: The project has clarified that the documentation was incorrect, and th...2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-3479 Impact, Exploitability, and Mitigation Steps | Wiz

💬Community

12
Bugzilla
CVE-2026-3479 python3.14: Python pkgutil.get_data(): Path Traversal via improper resource argument validation [fedora-all]2026-03-19
Bugzilla
CVE-2026-3479 python3.10: Python pkgutil.get_data(): Path Traversal via improper resource argument validation [fedora-all]2026-03-19
Bugzilla
CVE-2026-3479 python3.13: Python pkgutil.get_data(): Path Traversal via improper resource argument validation [fedora-all]2026-03-19
Bugzilla
CVE-2026-3479 asahi-installer: Python pkgutil.get_data(): Path Traversal via improper resource argument validation [fedora-all]2026-03-19
Bugzilla
CVE-2026-3479 mingw-python3: Python pkgutil.get_data(): Path Traversal via improper resource argument validation [fedora-all]2026-03-19
CVE-2026-3479 — Path Traversal | cvebase