ΠΠΎΠ»ΠΈΡΠ΅ΡΡΠ²ΠΎ 36
ΠΠΎΠ»ΠΈΡΠ΅ΡΡΠ²ΠΎ 36
GHSA-4g4g-fqw4-prp2
Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata. You are affected by this vulnerability if using the tarfileΒ module to extract untrusted tar archives using TarFile.extractall()Β or TarFile.extract()Β using the filter=Β parameter with a value of "data"Β or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter Β for more information. Only Python versions 3.12 or later are affected by these vulnerabilities, earlier versions don't include the extraction filter feature. Note that for Python 3.14 or later the default value of filter=Β changed from "no filtering" to `"data", so if you are relying on this new default behavior then your usage is also affected. Note that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions...
CVE-2025-4138
Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata. You are affected by this vulnerability if using the tarfileΒ module to extract untrusted tar archives using TarFile.extractall()Β or TarFile.extract()Β using the filter=Β parameter with a value of "data"Β or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter for more information. Note that for Python 3.14 or later the default value of filter=Β changed from "no filtering" to `"data", so if you are relying on this new default behavior then your usage is also affected. Note that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid install...
CVE-2025-4138
Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata. You are affected by this vulnerability if using the tarfileΒ module to extract untrusted tar archives using TarFile.extractall()Β or TarFile.extract()Β using the filter=Β parameter with a value of "data"Β or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter Β for more information. Note that for Python 3.14 or later the default value of filter=Β changed from "no filtering" to `"data", so if you are relying on this new default behavior then your usage is also affected. Note that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid insta...
CVE-2025-4138
Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata. You are affected by this vulnerability if using the tarfileΒ module to extract untrusted tar archives using TarFile.extractall()Β or TarFile.extract()Β using the filter=Β parameter with a value of "data"Β or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter Β for more information. Note that for Python 3.14 or later the default value of filter=Β changed from "no filtering" to `"data", so if you are relying on this new default behavior then your usage is also affected. Note that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid inst
CVE-2025-4138
Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory
CVE-2025-4138
Allows the extraction filter to be ignored, allowing symlink targets t ...
BDU:2025-09992
Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡΡ ΠΌΠΎΠ΄ΡΠ»Ρ tarfile ΠΈΠ½ΡΠ΅ΡΠΏΡΠ΅ΡΠ°ΡΠΎΡΠ° ΡΠ·ΡΠΊΠ° ΠΏΡΠΎΠ³ΡΠ°ΠΌΠΌΠΈΡΠΎΠ²Π°Π½ΠΈΡ Python (CPython), ΠΏΠΎΠ·Π²ΠΎΠ»ΡΡΡΠ°Ρ Π½Π°ΡΡΡΠΈΡΠ΅Π»Ρ ΠΏΠΎΠ»ΡΡΠΈΡΡ Π½Π΅ΡΠ°Π½ΠΊΡΠΈΠΎΠ½ΠΈΡΠΎΠ²Π°Π½Π½ΡΠΉ Π΄ΠΎΡΡΡΠΏ ΠΊ Π·Π°ΡΠΈΡΠ°Π΅ΠΌΠΎΠΉ ΠΈΠ½ΡΠΎΡΠΌΠ°ΡΠΈΠΈ
SUSE-SU-2025:02057-1
Security update for python311
SUSE-SU-2025:02050-1
Security update for python39
SUSE-SU-2025:02049-1
Security update for python311
SUSE-SU-2025:02048-1
Security update for python312
SUSE-SU-2025:02047-1
Security update for python310
RLSA-2025:10189
Important: python3.12 security update
RLSA-2025:10148
Important: python3.11 security update
RLSA-2025:10140
Important: python3.12 security update
RLSA-2025:10136
Important: python3.9 security update
RLSA-2025:10128
Important: python3 security update
RLSA-2025:10031
Important: python3.12 security update
RLSA-2025:10026
Important: python3.11 security update
ELSA-2025-10189
ELSA-2025-10189: python3.12 security update (IMPORTANT)
Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡΠ΅ΠΉ Π½Π° ΡΡΡΠ°Π½ΠΈΡΡ
Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡΡ | CVSS | EPSS | ΠΠΏΡΠ±Π»ΠΈΠΊΠΎΠ²Π°Π½ΠΎ | |
|---|---|---|---|---|
GHSA-4g4g-fqw4-prp2 Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata. You are affected by this vulnerability if using the tarfileΒ module to extract untrusted tar archives using TarFile.extractall()Β or TarFile.extract()Β using the filter=Β parameter with a value of "data"Β or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter Β for more information. Only Python versions 3.12 or later are affected by these vulnerabilities, earlier versions don't include the extraction filter feature. Note that for Python 3.14 or later the default value of filter=Β changed from "no filtering" to `"data", so if you are relying on this new default behavior then your usage is also affected. Note that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions... | CVSS3: 7.5 | 1% ΠΠΈΠ·ΠΊΠΈΠΉ | Π±ΠΎΠ»ΡΡΠ΅ 1 Π³ΠΎΠ΄Π° Π½Π°Π·Π°Π΄ | |
CVE-2025-4138 Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata. You are affected by this vulnerability if using the tarfileΒ module to extract untrusted tar archives using TarFile.extractall()Β or TarFile.extract()Β using the filter=Β parameter with a value of "data"Β or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter for more information. Note that for Python 3.14 or later the default value of filter=Β changed from "no filtering" to `"data", so if you are relying on this new default behavior then your usage is also affected. Note that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid install... | CVSS3: 7.5 | 1% ΠΠΈΠ·ΠΊΠΈΠΉ | Π±ΠΎΠ»ΡΡΠ΅ 1 Π³ΠΎΠ΄Π° Π½Π°Π·Π°Π΄ | |
CVE-2025-4138 Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata. You are affected by this vulnerability if using the tarfileΒ module to extract untrusted tar archives using TarFile.extractall()Β or TarFile.extract()Β using the filter=Β parameter with a value of "data"Β or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter Β for more information. Note that for Python 3.14 or later the default value of filter=Β changed from "no filtering" to `"data", so if you are relying on this new default behavior then your usage is also affected. Note that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid insta... | CVSS3: 7.5 | 1% ΠΠΈΠ·ΠΊΠΈΠΉ | Π±ΠΎΠ»ΡΡΠ΅ 1 Π³ΠΎΠ΄Π° Π½Π°Π·Π°Π΄ | |
CVE-2025-4138 Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata. You are affected by this vulnerability if using the tarfileΒ module to extract untrusted tar archives using TarFile.extractall()Β or TarFile.extract()Β using the filter=Β parameter with a value of "data"Β or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter Β for more information. Note that for Python 3.14 or later the default value of filter=Β changed from "no filtering" to `"data", so if you are relying on this new default behavior then your usage is also affected. Note that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid inst | CVSS3: 7.5 | 1% ΠΠΈΠ·ΠΊΠΈΠΉ | Π±ΠΎΠ»ΡΡΠ΅ 1 Π³ΠΎΠ΄Π° Π½Π°Π·Π°Π΄ | |
CVE-2025-4138 Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory | CVSS3: 7.5 | 1% ΠΠΈΠ·ΠΊΠΈΠΉ | ΠΎΠΊΠΎΠ»ΠΎ 1 Π³ΠΎΠ΄Π° Π½Π°Π·Π°Π΄ | |
CVE-2025-4138 Allows the extraction filter to be ignored, allowing symlink targets t ... | CVSS3: 7.5 | 1% ΠΠΈΠ·ΠΊΠΈΠΉ | Π±ΠΎΠ»ΡΡΠ΅ 1 Π³ΠΎΠ΄Π° Π½Π°Π·Π°Π΄ | |
BDU:2025-09992 Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡΡ ΠΌΠΎΠ΄ΡΠ»Ρ tarfile ΠΈΠ½ΡΠ΅ΡΠΏΡΠ΅ΡΠ°ΡΠΎΡΠ° ΡΠ·ΡΠΊΠ° ΠΏΡΠΎΠ³ΡΠ°ΠΌΠΌΠΈΡΠΎΠ²Π°Π½ΠΈΡ Python (CPython), ΠΏΠΎΠ·Π²ΠΎΠ»ΡΡΡΠ°Ρ Π½Π°ΡΡΡΠΈΡΠ΅Π»Ρ ΠΏΠΎΠ»ΡΡΠΈΡΡ Π½Π΅ΡΠ°Π½ΠΊΡΠΈΠΎΠ½ΠΈΡΠΎΠ²Π°Π½Π½ΡΠΉ Π΄ΠΎΡΡΡΠΏ ΠΊ Π·Π°ΡΠΈΡΠ°Π΅ΠΌΠΎΠΉ ΠΈΠ½ΡΠΎΡΠΌΠ°ΡΠΈΠΈ | CVSS3: 7.5 | 1% ΠΠΈΠ·ΠΊΠΈΠΉ | Π±ΠΎΠ»ΡΡΠ΅ 1 Π³ΠΎΠ΄Π° Π½Π°Π·Π°Π΄ | |
SUSE-SU-2025:02057-1 Security update for python311 | ΠΎΠΊΠΎΠ»ΠΎ 1 Π³ΠΎΠ΄Π° Π½Π°Π·Π°Π΄ | |||
SUSE-SU-2025:02050-1 Security update for python39 | ΠΎΠΊΠΎΠ»ΠΎ 1 Π³ΠΎΠ΄Π° Π½Π°Π·Π°Π΄ | |||
SUSE-SU-2025:02049-1 Security update for python311 | ΠΎΠΊΠΎΠ»ΠΎ 1 Π³ΠΎΠ΄Π° Π½Π°Π·Π°Π΄ | |||
SUSE-SU-2025:02048-1 Security update for python312 | ΠΎΠΊΠΎΠ»ΠΎ 1 Π³ΠΎΠ΄Π° Π½Π°Π·Π°Π΄ | |||
SUSE-SU-2025:02047-1 Security update for python310 | ΠΎΠΊΠΎΠ»ΠΎ 1 Π³ΠΎΠ΄Π° Π½Π°Π·Π°Π΄ | |||
RLSA-2025:10189 Important: python3.12 security update | 12 ΠΌΠ΅ΡΡΡΠ΅Π² Π½Π°Π·Π°Π΄ | |||
RLSA-2025:10148 Important: python3.11 security update | 12 ΠΌΠ΅ΡΡΡΠ΅Π² Π½Π°Π·Π°Π΄ | |||
RLSA-2025:10140 Important: python3.12 security update | 12 ΠΌΠ΅ΡΡΡΠ΅Π² Π½Π°Π·Π°Π΄ | |||
RLSA-2025:10136 Important: python3.9 security update | 12 ΠΌΠ΅ΡΡΡΠ΅Π² Π½Π°Π·Π°Π΄ | |||
RLSA-2025:10128 Important: python3 security update | 4 ΠΌΠ΅ΡΡΡΠ° Π½Π°Π·Π°Π΄ | |||
RLSA-2025:10031 Important: python3.12 security update | ΠΎΠΊΠΎΠ»ΠΎ 1 Π³ΠΎΠ΄Π° Π½Π°Π·Π°Π΄ | |||
RLSA-2025:10026 Important: python3.11 security update | ΠΎΠΊΠΎΠ»ΠΎ 1 Π³ΠΎΠ΄Π° Π½Π°Π·Π°Π΄ | |||
ELSA-2025-10189 ELSA-2025-10189: python3.12 security update (IMPORTANT) | ΠΎΠΊΠΎΠ»ΠΎ 1 Π³ΠΎΠ΄Π° Π½Π°Π·Π°Π΄ |
Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡΠ΅ΠΉ Π½Π° ΡΡΡΠ°Π½ΠΈΡΡ