Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-3479

12
FAUCET Score

CVE-2026-3479 describes a path traversal vulnerability within the pkgutil.get_data() function, stemming from inadequate validation of the resource argument, though no specific affected products are detailed. This vulnerability is rated with a low CVSS 4.0 score of 2.1, indicating a local attack vector with low complexity, primarily impacting data integrity. There is currently no evidence of active exploitation, public exploit code availability, or significant community discussion regarding this issue.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, < 3.13.13CPE match
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.14.0, < 3.14.4CPE match
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

0.0NONE

CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
LOW
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.24%
Probability of exploitation in next 30 days
EPSS Percentile
15.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0024 is in the 0th percentile among its peer group of 1 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 1.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

microsoft2026-Mar/CVE-2026-3479Low

pkgutil.get_data() does not enforce documented restrictions

Mar 10, 2026

References

github.com / python/cpython/commit/5af6ce3e7b643a30a02d22245c1e3f4a8bc0a1fe
github.com / python/cpython/commit/bcdf231946b1da8bdfbab4c05539bb0cc964a1c7
github.com / python/cpython/commit/cf59bf76470f3d75ad47d80ffb8ce76b64b5e943
github.com / python/cpython/commit/d786d59a8f7196bb630100a869f28ad13436b59c
github.com / python/cpython/issues/146121
github.com / python/cpython/pull/146122
mail.python.org / archives/list/[email protected]/thread/WYLLVQOOCKGK73JM7Z7ZSNOJC4N7BAWY