CVE-2026-7774
published 2026-06-04CVE-2026-7774: tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members…
PriorityP337medium6.9CVSS 4.0
AVNACLATNPRNUIAVCNVIHVANSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.62%
45.8th percentile
tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| python36_3.6 | python36 | — | — |
| python_software_foundation | cpython | < 3.13.14 | 3.13.14 |
| python_software_foundation | cpython | >= 3.14.0 < 3.14.6 | 3.14.6 |
| python_software_foundation | cpython | >= 3.15.0a1 < 3.15.0b2 | 3.15.0b2 |
| ubuntu | python3.10 | — | — |
| ubuntu | python3.12 | — | — |
| ubuntu | python3.14 | — | — |
CVSS provenance
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat6.9MEDIUM
vendor_ubuntu3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Python CPython up to 3.14.x Link tarfile.extractall path traversal (ID 149486 / EUVD-2026-34282)
vuldb·2026-06-04·CVSS 6.9
CVE-2026-7774 [MEDIUM] Python CPython up to 3.14.x Link tarfile.extractall path traversal (ID 149486 / EUVD-2026-34282)
A vulnerability, which was classified as critical, was found in Python CPython up to 3.14.x. Impacted is the function tarfile.extractall of the component Link Handler. Such manipulation leads to path traversal.
This vulnerability is traded as CVE-2026-7774. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.
GHSA
tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory.
ghsa_unreviewed·2026-06-04
CVE-2026-7774 [MEDIUM] CWE-22 tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory.
tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.
Ubuntu
Python vulnerabilities
vendor_ubuntu·2026-07-06·CVSS 3.3
CVE-2026-9669 [LOW] Python vulnerabilities
Title: Python vulnerabilities
Summary: Several security issues were fixed in Python.
It was discovered that Python incorrectly normalized paths in the tarfile
module. An attacker could possibly use this issue to bypass path
restrictions. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04
LTS. (CVE-2025-13462)
It was discovered that Python's HTMLParser incorrectly handled certain
malformed HTML input. An attacker could possibly use this issue to cause
Python to crash, resulting in a denial of service. This issue only affected
Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2025-69534)
It was discovered that Python's email module incorrectly quoted newlines
in headers. An attacker could possibly use this issue to inject arbitrary
email headers. This issue only affected Ubuntu 22.04 L
Red Hat
python: CPython: Python tarfile: Arbitrary file write via crafted link entries
vendor_redhat·2026-06-04·CVSS 6.9
CVE-2026-7774 [MEDIUM] CWE-59 python: CPython: Python tarfile: Arbitrary file write via crafted link entries
python: CPython: Python tarfile: Arbitrary file write via crafted link entries
tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.
A flaw was found in the `tarfile.data_filter` function within the Python `tarfile` module. A remote attacker could exploit this vulnerability by providing a specially crafted tar archive containing malicious link entries, such as symlinks with empty or directory-like names. This bypass allows the attacker to redirect subsequent archive members outs
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-7774 mercurial: Python tarfile: Arbitrary file write via crafted link entries [epel-all]
bugzilla·2026-06-17·CVSS 6.9
CVE-2026-7774 [MEDIUM] CVE-2026-7774 mercurial: Python tarfile: Arbitrary file write via crafted link entries [epel-all]
CVE-2026-7774 mercurial: Python tarfile: Arbitrary file write via crafted link entries [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
Please clarify why this issue was created for the Mercurial package and what action is expected.
Bugzilla
CVE-2026-7774 mercurial: Python tarfile: Arbitrary file write via crafted link entries [fedora-all]
bugzilla·2026-06-17·CVSS 6.9
CVE-2026-7774 [MEDIUM] CVE-2026-7774 mercurial: Python tarfile: Arbitrary file write via crafted link entries [fedora-all]
CVE-2026-7774 mercurial: Python tarfile: Arbitrary file write via crafted link entries [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
Please clarify why this issue was created for the Mercurial package and what action is expected.
Bugzilla
CVE-2026-7774 python: CPython: Python tarfile: Arbitrary file write via crafted link entries
bugzilla·2026-06-04·CVSS 6.9
CVE-2026-7774 [MEDIUM] CVE-2026-7774 python: CPython: Python tarfile: Arbitrary file write via crafted link entries
CVE-2026-7774 python: CPython: Python tarfile: Arbitrary file write via crafted link entries
tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.
https://github.com/python/cpython/commit/0478bd83d82b255e0f29f613367a59d261e7eaa2https://github.com/python/cpython/commit/0d28f5e46e151718972dfabd91205444d0037b6dhttps://github.com/python/cpython/commit/10a13bee3c24f9c62b602e696334ff2272a40efchttps://github.com/python/cpython/commit/578411982c16f753f4893532510099ef665117dahttps://github.com/python/cpython/commit/5cf47a248c35c375d610b87b2f72fd1ed454b558https://github.com/python/cpython/commit/74cca9a92fb7d653e404843a56b8bdc7b0afdbbfhttps://github.com/python/cpython/commit/c063191cb7f9170f9565e305f8aa2b79ab2bf609https://github.com/python/cpython/issues/149486https://github.com/python/cpython/pull/149487https://mail.python.org/archives/list/[email protected]/thread/4FU62L2M6RMMHT2QPGQNPEHHUND7CEX5/http://www.openwall.com/lists/oss-security/2026/06/04/9
2026-06-04
Published