When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None.
https://mail.python.org/archives/list/[email protected]/thread/57TBTLL2W6APMZR3A25B2YV7GL3EPTDJ/
https://github.com/python/cpython/pull/157266
https://github.com/python/cpython/issues/157265
https://github.com/python/cpython/commit/fb2f0bbc3b35264f09cc2cb2934b7987527a6bc2
https://github.com/python/cpython/commit/d9565e54b1fc6d63c5be9afd58114499128fa57b
https://github.com/python/cpython/commit/c1f106d240c4ffcb3608ed0a20e8aba6c865f6d3
https://github.com/python/cpython/commit/a4919937a4e1e69a0d178909c6f20557eca5d1d0
https://github.com/python/cpython/commit/9c17bace90f88dfba6d0e2fe23c8e7ae35f83955
https://github.com/python/cpython/commit/764fd0af8d9e19d3684a58d2e58bf770f0605036
https://github.com/python/cpython/commit/3105a3498aaf681ce128cf5baf83c2e5574267c5
https://github.com/python/cpython/commit/2eb0c2f1dc71847731b6ab30aebefd058d482a7f
Published: 2026-09-11
Updated: 2026-10-03
Named Vulnerability: GHSA-rj44-3777-mh5x
Base Score: 7.5
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P
Severity: High
Base Score: 9.1
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Severity: Critical
Base Score: 5.7
Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Severity: Medium
EPSS: 0.00423