CVE-2026-87910

medium

Description

When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None.

References

https://mail.python.org/archives/list/[email protected]/thread/57TBTLL2W6APMZR3A25B2YV7GL3EPTDJ/

https://github.com/python/cpython/pull/157266

https://github.com/python/cpython/issues/157265

https://github.com/python/cpython/commit/fb2f0bbc3b35264f09cc2cb2934b7987527a6bc2

https://github.com/python/cpython/commit/d9565e54b1fc6d63c5be9afd58114499128fa57b

http://www.openwall.com/lists/oss-security/2026/09/11/8

Details

Source: Mitre, NVD

Published: 2026-09-11

Updated: 2026-09-12

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.1

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Severity: Critical

CVSS v4

Base Score: 5.7

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Severity: Medium

EPSS

EPSS: 0.00423