Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-11940

34
FAUCET Score

tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a deeper name than the hardlink itself.  The extraction fallback validated the symlink at it's archived location but recreated it at the hardlink's shallower path, letting a relative target the filter judged contained escape the destination directory.  This allowed a malicious tar archive to create a symlink pointing outside the destination, enabling out-of-destination file reads or writes. This was an incomplete fix of CVE-2025-4330.

First published: Jun 23, 2026Last modified: Jul 23, 2026

Impacted Technologies

VendorProductVersion(s)CPE
Python Software FoundationCPython
>= 0, < 3.15.0b4CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 4.0

7.8HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
HIGH
SS Integrity
HIGH
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.63%
Probability of exploitation in next 30 days
EPSS Percentile
46.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0063 is in the 23rd percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f
github.com / python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df
github.com / python/cpython/commit/771d12dda5140313db0ac550292987975651bbde
github.com / python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c
github.com / python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9
github.com / python/cpython/issues/151558
github.com / python/cpython/pull/151559
mail.python.org / archives/list/[email protected]/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH