CVE-2026-3087
EUVD-2026-2592227.04.2026, 21:16
If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems. Only Windows is affected by this vulnerability.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| python | python | 𝑥 ≤ 3.14.4 |
| python | python | 3.15.0:alpha1 |
| python | python | 3.15.0:alpha2 |
| python | python | 3.15.0:alpha3 |
| python | python | 3.15.0:alpha4 |
| python | python | 3.15.0:alpha5 |
| python | python | 3.15.0:alpha6 |
| python | python | 3.15.0:alpha7 |
| python | python | 3.15.0:alpha8 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| python | cpython | 𝑥 < 3.13.14 | CNA |
Debian Releases
Debian Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| pypy3 |
| ||||||||||||
| python3.11 |
| ||||||||||||
| python3.13 |
| ||||||||||||
| python3.14 |
| ||||||||||||
| python3.9 |
|
References