Описание
pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.
pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2026-3479
- https://github.com/python/cpython/issues/146121
- https://github.com/python/cpython/pull/146122
- https://github.com/python/cpython/commit/bcdf231946b1da8bdfbab4c05539bb0cc964a1c7
- https://mail.python.org/archives/list/security-announce@python.org/thread/WYLLVQOOCKGK73JM7Z7ZSNOJC4N7BAWY
Связанные уязвимости
nvd
8 дней назад
pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.
debian
8 дней назад
pkgutil.get_data() did not validate the resource argument as documente ...