CVE-2026-41140

EUVD-2026-25578
Poetry is a dependency manager for Python. Prior to 2.3.4, the extractall() function in src/poetry/utils/helpers.py:410-426 extracts sdist tarballs without path traversal protection on Python versions where tarfile.data_filter is unavailable. Considering only Python versions which are still supported by Poetry, these are 3.10.0 - 3.10.12 and 3.11.0 - 3.11.4. This vulnerability is fixed in 2.3.4.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.7 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 21.63%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatRed Hat Ansible Automation Platform 2.6
1779761061 ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.6
1780102732 ≤
𝑥
< *
ADP
Debian logo
Debian Releases
Debian Product
Codename
poetry
bookworm
no-dsa
forky
2.3.4-2
fixed
sid
2.3.4-2
fixed
trixie
2.1.2+dfsg-1+deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
poetry
jammy
needed
noble
needed
questing
ignored
resolute
needed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
poetry
Azure Linux 3.0
0:1.8.5-2.azl3
fixed