Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2571▼ 329 respecto a la semana anterior
Críticas / altas1341▲ 75 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.7) | 0.64% | — | Python TarfileAI | 11/9/2026 | 2/10/2026 | When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the… | |
| Pendiente de análisis | Media (6.3) | 0.52% | — | Python TarfileAI | 19/8/2026 | 28/8/2026 | The tarfile module's tar and data extraction filters created directories outside the destination for members whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given. Only empty… | |
| Pendiente de análisis | Alta (8.2) | 0.71% | — | Python TarfileAI | 23/6/2026 | 13/8/2026 | When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer. | |
| Pendiente de análisis | Alta (7.8) | 0.75% | — | Python TarfileAI | 23/6/2026 | 13/8/2026 | tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a deeper name than the hardlink itself. The extraction fallback validated the symlink at it's archived location but recreated it at the hardlink's shallower path, letting a… | |
| Pendiente de análisis | Media (6.9) | 0.78% | — | Python TarfileAI | 4/6/2026 | 13/8/2026 | tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory,… | |
| Aplazada | Crítica (9.4) | 1.4% | — | Python TarfileAI | 3/6/2025 | 31/7/2026 | Allows arbitrary filesystem writes outside the extraction directory during extraction with filter="data". You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of "data" or "tar". See… | |
| Aplazada | Alta (7.5) | 0.59% | — | Python TarfileAI | 3/6/2025 | 31/7/2026 | When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that the member would still be extracted and not skipped. | |
| Aplazada | Alta (7.5) | 0.94% | — | Python TarfileAI | 3/6/2025 | 31/7/2026 | Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata. You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the… |