Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-3479

Опубликовано: 18 мар. 2026
Источник: debian
EPSS Низкий

Описание

DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model. pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python3.14unfixedpackage
python3.13unfixedpackage
python3.11removedpackage
python3.9removedpackage
python2.7removedpackage
pypy3unfixedpackage

Примечания

  • https://mail.python.org/archives/list/security-announce@python.org/thread/WYLLVQOOCKGK73JM7Z7ZSNOJC4N7BAWY/

  • Not considered a security issue

  • https://github.com/python/cpython/issues/146121

  • https://github.com/python/cpython/pull/146133 (3.14)

  • https://github.com/python/cpython/pull/146134 (3.13)

  • https://github.com/python/cpython/pull/146136 (3.11)

EPSS

Процентиль: 15%
0.00238
Низкий

Связанные уязвимости

ubuntu
5 месяцев назад

DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model. pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.

CVSS3: 3.3
redhat
5 месяцев назад

DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model. pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.

nvd
5 месяцев назад

DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model. pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.

msrc
4 месяца назад

pkgutil.get_data() does not enforce documented restrictions

suse-cvrf
4 месяца назад

Security update for python

EPSS

Процентиль: 15%
0.00238
Низкий