CVE-2026-3087

EUVD-2026-25922
If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems. Only Windows is affected by this vulnerability.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
PSFCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 35%
Affected Products (NVD)
VendorProductVersion
pythonpython
𝑥
≤ 3.14.4
pythonpython
3.15.0:alpha1
pythonpython
3.15.0:alpha2
pythonpython
3.15.0:alpha3
pythonpython
3.15.0:alpha4
pythonpython
3.15.0:alpha5
pythonpython
3.15.0:alpha6
pythonpython
3.15.0:alpha7
pythonpython
3.15.0:alpha8
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
pythoncpython
𝑥
< 3.13.14
CNA
Debian logo
Debian Releases
Debian Product
Codename
pypy3
bookworm
7.3.11+dfsg-2+deb12u3
fixed
bullseye
7.3.5+dfsg-2+deb11u2
fixed
bullseye (security)
7.3.5+dfsg-2+deb11u5
fixed
forky
7.3.23+dfsg-1
fixed
sid
7.3.23+dfsg-1
fixed
trixie
7.3.19+dfsg-2
fixed
python3.11
bookworm
3.11.2-6+deb12u7
fixed
bookworm (security)
3.11.2-6+deb12u3
fixed
python3.13
forky
3.13.12-1
fixed
sid
3.13.14-1
fixed
trixie
3.13.5-2+deb13u2
fixed
python3.14
forky
3.14.5-1
fixed
sid
3.14.6-1
fixed
python3.9
bullseye
3.9.2-1
fixed
bullseye (security)
3.9.2-1+deb11u7
fixed