---
cve: "CVE-2026-11940"
severity: "HIGH"
cvss: 7.8
epss: "75%"
vendor: "Python Software Foundation"
kev: false
exploited: false
published: "2026-06-23 17:16:40"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-09T03:50:13+02:00"
---

# CVE-2026-11940

> 7.8 HIGH · 🧪 PoC

## Beschreibung

tarfile.extractall() with the 'data' or 'tar'
 filter could be bypassed by a crafted archive where a hardlink 
references a symlink stored at a deeper name than the hardlink itself.  
The extraction fallback validated the symlink at it's archived location 
but recreated it at the hardlink's shallower
path, letting a relative
 target the filter judged contained escape the destination directory.  
This allowed a malicious tar archive to create a symlink pointing 
outside the destination, enabling out-of-destination file reads or 
writes. This was an incomplete fix of CVE-2025-4330.

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |

## Patch verfügbar (OSV)

- 3a19c2f0b3e91ce8f23d0cc64d4c9ee557823f24 (Commit)
- 41388c9cb160d0886d5ca00d2e6c8782608a4549 (Commit)

## Referenzen

- <https://github.com/python/cpython/pull/151559>
- <https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/>
- <https://github.com/python/cpython/issues/151558>
- <https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f>
- <https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df>
- <https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde>
- <https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c>
- <https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9>
- <https://github.com/python/cpython/commit/e5fdbd8d5aa923bd9111b112ea73bd6ec7c47877>
- <https://github.com/python/cpython/commit/0f852b3f07dd8e71e40326a51c02afbf16a42cc5>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-11940) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
