Количество 15
Количество 15
CVE-2026-7774
tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.
CVE-2026-7774
tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.
CVE-2026-7774
tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.
CVE-2026-7774
tarfile.data_filter path traversal bypass allows writing outside the extraction directory
CVE-2026-7774
tarfile.data_filter could be bypassed using crafted link entries, incl ...
SUSE-SU-2026:3851-1
Security update for python310
GHSA-6cj7-v55x-8mwr
tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.
SUSE-SU-2026:4174-1
Security update for python39.SUSE_SLE-15-SP3_Update
SUSE-SU-2026:3569-1
Security update for python312
SUSE-SU-2026:3560-1
Security update for python311
SUSE-SU-2026:3548-1
Security update for python311
SUSE-SU-2026:3530-1
Security update for python310
SUSE-SU-2026:3601-1
Security update for python3
SUSE-SU-2026:3649-1
Security update for python313
SUSE-SU-2026:3855-1
Security update for python36
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-7774 tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process. | 1% Низкий | 4 месяца назад | ||
CVE-2026-7774 tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process. | CVSS3: 6.5 | 1% Низкий | 4 месяца назад | |
CVE-2026-7774 tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process. | 1% Низкий | 4 месяца назад | ||
CVE-2026-7774 tarfile.data_filter path traversal bypass allows writing outside the extraction directory | 1% Низкий | 3 месяца назад | ||
CVE-2026-7774 tarfile.data_filter could be bypassed using crafted link entries, incl ... | 1% Низкий | 4 месяца назад | ||
SUSE-SU-2026:3851-1 Security update for python310 | 1% Низкий | 20 дней назад | ||
GHSA-6cj7-v55x-8mwr tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process. | 1% Низкий | 3 месяца назад | ||
SUSE-SU-2026:4174-1 Security update for python39.SUSE_SLE-15-SP3_Update | 3 дня назад | |||
SUSE-SU-2026:3569-1 Security update for python312 | около 1 месяца назад | |||
SUSE-SU-2026:3560-1 Security update for python311 | около 1 месяца назад | |||
SUSE-SU-2026:3548-1 Security update for python311 | около 1 месяца назад | |||
SUSE-SU-2026:3530-1 Security update for python310 | около 1 месяца назад | |||
SUSE-SU-2026:3601-1 Security update for python3 | около 1 месяца назад | |||
SUSE-SU-2026:3649-1 Security update for python313 | 29 дней назад | |||
SUSE-SU-2026:3855-1 Security update for python36 | 20 дней назад |
Уязвимостей на страницу