Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2844 articles · 109910 vulns · 38/41 feeds (7d)
← Back to list
—
CVE-2025-13462PATCHED
python software foundation · cpython

tarfile: Skip DIRTYPE normalization during GNU LONGNAME/LONGLINK handling

Description

The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations.

Affected Products

VendorProductVersions
python software foundationcpython0, 3.14.0, 3.15.0a1

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
open sourcepythoncert_advisory90%
sususe opensusecert_advisory90%

References

  • https://github.com/python/cpython/pull/143934(patch)
  • https://github.com/python/cpython/issues/141707(issue-tracking)
  • https://mail.python.org/archives/list/security-announce@python.org/thread/EOMI5I66ZMKQ2INNFT6T7IAIKUGPZYIE/(vendor-advisory)
  • https://github.com/python/cpython/commit/42d754e34c06e57ad6b8e7f92f32af679912d8ab(patch)
  • https://github.com/python/cpython/commit/7ad3093d76a748af55bdb1d2e8aad3638163b017(patch)
  • https://github.com/python/cpython/commit/ae99fe3a33b43e303a05f012815cef60b611a9c7(patch)

Related News (1 articles)

Tier B
BSI Advisories3d ago
[UPDATE] [niedrig] CPython: Schwachstelle ermöglicht Manipulation von Dateien
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
Patch available
3.14.43.15.0a8
PublishedMar 12, 2026
Last enriched9d ago
Trending Score12
Source articles1
Independent1
Info Completeness4/14
Missing: vendor, product, versions, cvss, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-34591EXP
Poetry Has Wheel Path Traversal Which Can Lead to Arbitrary File Write
Trending: 38
HIGHCVE-2026-1502
HTTP client proxy tunnel headers not validated for CR/LF
Trending: 27
NONECVE-2026-3446
Base64 decoding stops at first padded quad by default
Trending: 20
NONECVE-2026-4519EXP
webbrowser.open() allows leading dashes in URLs
Trending: 14
NONECVE-2026-3644
Incomplete control character validation in http.cookies
Trending: 5

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Mar 12, 2026
Discovered by ZDM
Apr 1, 2026
Patch Available
Apr 7, 2026