CVE-2026-3479

EUVD-2026-12940
DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.

pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
PSFCNA
0 NONE
PHYSICAL
LOW
NONE
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 3%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
pythoncpython
𝑥
< 3.13.13
CNA
pythoncpython
3.14.0 ≤
𝑥
< 3.14.4
CNA
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libpython2_7-1_0
suse enterprise server 12 SP3
2.7.18-28.151.1
fixed
suse enterprise server 12 SP5
2.7.18-33.74.1
fixed
libpython2_7-1_0-32bit
suse enterprise server 12 SP3
2.7.18-28.151.1
fixed
suse enterprise server 12 SP5
2.7.18-33.74.1
fixed
libpython3_10-1_0
suse enterprise server 15 SP4
3.10.20-150400.4.107.1
fixed
libpython3_11-1_0
suse enterprise desktop 15 SP7
3.11.15-150600.3.53.1
fixed
suse enterprise sap 15 SP4
3.11.15-150400.9.85.1
fixed
suse enterprise sap 15 SP7
3.11.15-150600.3.53.1
fixed
suse enterprise server 15 SP4
3.11.15-150400.9.85.1
fixed
suse enterprise server 15 SP5
3.11.15-150400.9.85.1
fixed
suse enterprise server 15 SP6
3.11.15-150600.3.53.1
fixed
suse enterprise server 15 SP7
3.11.15-150600.3.53.1
fixed
libpython3_12-1_0
suse enterprise server 15 SP6
3.12.13-150600.3.53.1
fixed
libpython3_13-1_0
suse enterprise desktop 15 SP7
3.13.13-150700.4.45.1
fixed
suse enterprise sap 15 SP7
3.13.13-150700.4.45.1
fixed
suse enterprise server 15 SP7
3.13.13-150700.4.45.1
fixed
libpython3_4m1_0
suse enterprise server 12 SP3
3.4.10-25.180.1
fixed
suse enterprise server 12 SP5
3.4.10-25.180.1
fixed
libpython3_4m1_0-32bit
suse enterprise server 12 SP5
3.4.10-25.180.1
fixed
libpython3_6m1_0
suse enterprise server 12 SP3
3.6.15-6.151.2
fixed
suse enterprise server 12 SP5
3.6.15-108.1
fixed
libpython3_6m1_0-32bit
suse enterprise server 12 SP5
3.6.15-108.1
fixed
python
suse enterprise server 12 SP3
2.7.18-28.151.1
fixed
suse enterprise server 12 SP5
2.7.18-33.74.1
fixed
python-32bit
suse enterprise server 12 SP3
2.7.18-28.151.1
fixed
suse enterprise server 12 SP5
2.7.18-33.74.1
fixed
python-base
suse enterprise server 12 SP3
2.7.18-28.151.1
fixed
suse enterprise server 12 SP5
2.7.18-33.74.1
fixed
python-base-32bit
suse enterprise server 12 SP3
2.7.18-28.151.1
fixed
suse enterprise server 12 SP5
2.7.18-33.74.1
fixed
python-curses
suse enterprise server 12 SP3
2.7.18-28.151.1
fixed
suse enterprise server 12 SP5
2.7.18-33.74.1
fixed
python-demo
suse enterprise server 12 SP3
2.7.18-28.151.1
fixed
suse enterprise server 12 SP5
2.7.18-33.74.1
fixed
python-devel
suse enterprise server 12 SP3
2.7.18-28.151.1
fixed
suse enterprise server 12 SP5
2.7.18-33.74.1
fixed
python-doc
suse enterprise server 12 SP3
2.7.18-28.151.1
fixed
suse enterprise server 12 SP5
2.7.18-33.74.1
fixed
python-doc-pdf
suse enterprise server 12 SP3
2.7.18-28.151.1
fixed
suse enterprise server 12 SP5
2.7.18-33.74.1
fixed
python-gdbm
suse enterprise server 12 SP3
2.7.18-28.151.1
fixed
suse enterprise server 12 SP5
2.7.18-33.74.1
fixed
python-idle
suse enterprise server 12 SP3
2.7.18-28.151.1
fixed
suse enterprise server 12 SP5
2.7.18-33.74.1
fixed
python-tk
suse enterprise server 12 SP3
2.7.18-28.151.1
fixed
suse enterprise server 12 SP5
2.7.18-33.74.1
fixed
python-xml
suse enterprise server 12 SP3
2.7.18-28.151.1
fixed
suse enterprise server 12 SP5
2.7.18-33.74.1
fixed
python3
suse enterprise server 12 SP3
3.4.10-25.180.1
fixed
suse enterprise server 12 SP5
3.4.10-25.180.1
fixed
python3-base
suse enterprise server 12 SP3
3.4.10-25.180.1
fixed
suse enterprise server 12 SP5
3.4.10-25.180.1
fixed
python3-curses
suse enterprise server 12 SP3
3.4.10-25.180.1
fixed
suse enterprise server 12 SP5
3.4.10-25.180.1
fixed
python3-devel
suse enterprise server 12 SP5
3.4.10-25.180.1
fixed
python3-tk
suse enterprise server 12 SP5
3.4.10-25.180.1
fixed
python310
suse enterprise server 15 SP4
3.10.20-150400.4.107.1
fixed
python310-base
suse enterprise server 15 SP4
3.10.20-150400.4.107.1
fixed
python310-curses
suse enterprise server 15 SP4
3.10.20-150400.4.107.1
fixed
python310-dbm
suse enterprise server 15 SP4
3.10.20-150400.4.107.1
fixed
python310-devel
suse enterprise server 15 SP4
3.10.20-150400.4.107.1
fixed
python310-idle
suse enterprise server 15 SP4
3.10.20-150400.4.107.1
fixed
python310-tk
suse enterprise server 15 SP4
3.10.20-150400.4.107.1
fixed
python310-tools
suse enterprise server 15 SP4
3.10.20-150400.4.107.1
fixed
python311
suse enterprise desktop 15 SP7
3.11.15-150600.3.53.1
fixed
suse enterprise sap 15 SP4
3.11.15-150400.9.85.1
fixed
suse enterprise sap 15 SP7
3.11.15-150600.3.53.1
fixed
suse enterprise server 15 SP4
3.11.15-150400.9.85.1
fixed
suse enterprise server 15 SP5
3.11.15-150400.9.85.1
fixed
suse enterprise server 15 SP6
3.11.15-150600.3.53.1
fixed
suse enterprise server 15 SP7
3.11.15-150600.3.53.1
fixed
python311-base
suse enterprise desktop 15 SP7
3.11.15-150600.3.53.1
fixed
suse enterprise sap 15 SP4
3.11.15-150400.9.85.1
fixed
suse enterprise sap 15 SP7
3.11.15-150600.3.53.1
fixed
suse enterprise server 15 SP4
3.11.15-150400.9.85.1
fixed
suse enterprise server 15 SP5
3.11.15-150400.9.85.1
fixed
suse enterprise server 15 SP6
3.11.15-150600.3.53.1
fixed
suse enterprise server 15 SP7
3.11.15-150600.3.53.1
fixed
python311-curses
suse enterprise desktop 15 SP7
3.11.15-150600.3.53.1
fixed
suse enterprise sap 15 SP7
3.11.15-150600.3.53.1
fixed
suse enterprise server 15 SP4
3.11.15-150400.9.85.1
fixed
suse enterprise server 15 SP5
3.11.15-150400.9.85.1
fixed
suse enterprise server 15 SP6
3.11.15-150600.3.53.1
fixed
suse enterprise server 15 SP7
3.11.15-150600.3.53.1
fixed
python311-dbm
suse enterprise desktop 15 SP7
3.11.15-150600.3.53.1
fixed
suse enterprise sap 15 SP7
3.11.15-150600.3.53.1
fixed
suse enterprise server 15 SP4
3.11.15-150400.9.85.1
fixed
suse enterprise server 15 SP5
3.11.15-150400.9.85.1
fixed
suse enterprise server 15 SP6
3.11.15-150600.3.53.1
fixed
suse enterprise server 15 SP7
3.11.15-150600.3.53.1
fixed
python311-devel
suse enterprise desktop 15 SP7
3.11.15-150600.3.53.1
fixed
suse enterprise sap 15 SP7
3.11.15-150600.3.53.1
fixed
suse enterprise server 15 SP4
3.11.15-150400.9.85.1
fixed
suse enterprise server 15 SP5
3.11.15-150400.9.85.1
fixed
suse enterprise server 15 SP6
3.11.15-150600.3.53.1
fixed
suse enterprise server 15 SP7
3.11.15-150600.3.53.1
fixed
python311-doc
suse enterprise server 15 SP4
3.11.15-150400.9.85.1
fixed
suse enterprise server 15 SP5
3.11.15-150400.9.85.1
fixed
python311-doc-devhelp
suse enterprise server 15 SP4
3.11.15-150400.9.85.1
fixed
suse enterprise server 15 SP5
3.11.15-150400.9.85.1
fixed
python311-idle
suse enterprise desktop 15 SP7
3.11.15-150600.3.53.1
fixed
suse enterprise sap 15 SP7
3.11.15-150600.3.53.1
fixed
suse enterprise server 15 SP4
3.11.15-150400.9.85.1
fixed
suse enterprise server 15 SP5
3.11.15-150400.9.85.1
fixed
suse enterprise server 15 SP6
3.11.15-150600.3.53.1
fixed
suse enterprise server 15 SP7
3.11.15-150600.3.53.1
fixed
python311-tk
suse enterprise desktop 15 SP7
3.11.15-150600.3.53.1
fixed
suse enterprise sap 15 SP7
3.11.15-150600.3.53.1
fixed
suse enterprise server 15 SP4
3.11.15-150400.9.85.1
fixed
suse enterprise server 15 SP5
3.11.15-150400.9.85.1
fixed
suse enterprise server 15 SP6
3.11.15-150600.3.53.1
fixed
suse enterprise server 15 SP7
3.11.15-150600.3.53.1
fixed
python311-tools
suse enterprise desktop 15 SP7
3.11.15-150600.3.53.1
fixed
suse enterprise sap 15 SP7
3.11.15-150600.3.53.1
fixed
suse enterprise server 15 SP4
3.11.15-150400.9.85.1
fixed
suse enterprise server 15 SP5
3.11.15-150400.9.85.1
fixed
suse enterprise server 15 SP6
3.11.15-150600.3.53.1
fixed
suse enterprise server 15 SP7
3.11.15-150600.3.53.1
fixed
python312
suse enterprise server 15 SP6
3.12.13-150600.3.53.1
fixed
python312-base
suse enterprise server 15 SP6
3.12.13-150600.3.53.1
fixed
python312-curses
suse enterprise server 15 SP6
3.12.13-150600.3.53.1
fixed
python312-dbm
suse enterprise server 15 SP6
3.12.13-150600.3.53.1
fixed
python312-devel
suse enterprise server 15 SP6
3.12.13-150600.3.53.1
fixed
python312-idle
suse enterprise server 15 SP6
3.12.13-150600.3.53.1
fixed
python312-tk
suse enterprise server 15 SP6
3.12.13-150600.3.53.1
fixed
python312-tools
suse enterprise server 15 SP6
3.12.13-150600.3.53.1
fixed
python313
suse enterprise desktop 15 SP7
3.13.13-150700.4.45.1
fixed
suse enterprise sap 15 SP7
3.13.13-150700.4.45.1
fixed
suse enterprise server 15 SP7
3.13.13-150700.4.45.1
fixed
python313-base
suse enterprise desktop 15 SP7
3.13.13-150700.4.45.1
fixed
suse enterprise sap 15 SP7
3.13.13-150700.4.45.1
fixed
suse enterprise server 15 SP7
3.13.13-150700.4.45.1
fixed
python313-curses
suse enterprise desktop 15 SP7
3.13.13-150700.4.45.1
fixed
suse enterprise sap 15 SP7
3.13.13-150700.4.45.1
fixed
suse enterprise server 15 SP7
3.13.13-150700.4.45.1
fixed
python313-dbm
suse enterprise desktop 15 SP7
3.13.13-150700.4.45.1
fixed
suse enterprise sap 15 SP7
3.13.13-150700.4.45.1
fixed
suse enterprise server 15 SP7
3.13.13-150700.4.45.1
fixed
python313-devel
suse enterprise desktop 15 SP7
3.13.13-150700.4.45.1
fixed
suse enterprise sap 15 SP7
3.13.13-150700.4.45.1
fixed
suse enterprise server 15 SP7
3.13.13-150700.4.45.1
fixed
python313-idle
suse enterprise desktop 15 SP7
3.13.13-150700.4.45.1
fixed
suse enterprise sap 15 SP7
3.13.13-150700.4.45.1
fixed
suse enterprise server 15 SP7
3.13.13-150700.4.45.1
fixed
python313-tk
suse enterprise desktop 15 SP7
3.13.13-150700.4.45.1
fixed
suse enterprise sap 15 SP7
3.13.13-150700.4.45.1
fixed
suse enterprise server 15 SP7
3.13.13-150700.4.45.1
fixed
python313-tools
suse enterprise desktop 15 SP7
3.13.13-150700.4.45.1
fixed
suse enterprise sap 15 SP7
3.13.13-150700.4.45.1
fixed
suse enterprise server 15 SP7
3.13.13-150700.4.45.1
fixed
python36
suse enterprise server 12 SP3
3.6.15-6.151.2
fixed
suse enterprise server 12 SP5
3.6.15-108.1
fixed
python36-base
suse enterprise server 12 SP3
3.6.15-6.151.2
fixed
suse enterprise server 12 SP5
3.6.15-108.1
fixed
python36-curses
suse enterprise server 12 SP3
3.6.15-6.151.2
fixed
python36-dbm
suse enterprise server 12 SP3
3.6.15-6.151.2
fixed
python36-devel
suse enterprise server 12 SP3
3.6.15-6.151.2
fixed
suse enterprise server 12 SP5
3.6.15-108.1
fixed
python36-idle
suse enterprise server 12 SP3
3.6.15-6.151.2
fixed
python36-testsuite
suse enterprise server 12 SP3
3.6.15-6.151.2
fixed
python36-tk
suse enterprise server 12 SP3
3.6.15-6.151.2
fixed
python36-tools
suse enterprise server 12 SP3
3.6.15-6.151.2
fixed