THREATOPS
THREAT OPSThreat News › [CVE-2026-19672] CPython: tarfile extraction filter bypass allows creation of directories outside the destination

[CVE-2026-19672] CPython: tarfile extraction filter bypass allows creation of directories outside the destination

medoss_secPublished 2026-08-25

<p>Posted by Alan Coopersmith on Aug 25</p>-------- Forwarded Message --------<br /> Subject: [Security-announce][CVE-2026-19672] tarfile extraction filter bypass allows creation of directories <br /> outside the destination<br /> Date: Wed, 19 Aug 2026 14:56:06 +0100<br /> From: Stan Ulbrych via Security-announce &lt;security-announce () python org&gt;<br /> Reply-To: security-si

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/578