[Git][security-tracker-team/security-tracker][master] CVE-2026-4360: python3.11,python3.9,python2.7,jython not-affected, pypy3 postponed

Sylvain Beucler (@beuc) gitlab at salsa.debian.org
Mon Jul 13 12:04:52 BST 2026



Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker


Commits:
cf0b36ff by Sylvain Beucler at 2026-07-13T13:01:24+02:00
CVE-2026-4360: python3.11,python3.9,python2.7,jython not-affected, pypy3 postponed

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -8404,23 +8404,21 @@ CVE-2026-4360 (In the Tarfile.extract() function, the filter parameter is not pa
 	- python3.14 <unfixed>
 	- python3.13 <unfixed>
 	[trixie] - python3.13 <no-dsa> (Minor issue)
-	- python3.11 <removed>
-	- python3.9 <removed>
-	[bullseye] - python3.9 <not-affected> (extraction filters (PEP 706) absent in 3.9.2; extract() has no filter parameter)
-	- python2.7 <removed>
-	[bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
-	- jython <unfixed>
-	[trixie] - jython <no-dsa> (Minor issue)
-	[bookworm] - jython <not-affected> (extraction filters/PEP 706 absent in bundled python2.7 stdlib; tarfile.extract() has no filter parameter)
-	[bullseye] - jython <end-of-life> (EOL in bullseye LTS)
+	- python3.11 <not-affected> (Vulnerable code didn't get backported to the version in Bookworm)
+	- python3.9 <not-affected> (extraction filters (PEP 706) absent in 3.9.2; extract() has no filter parameter)
+	- python2.7 <not-affected> (extraction filters (PEP 706) absent in py2; extract() has no filter parameter)
+	- jython <not-affected> (extraction filters/PEP 706 absent in bundled python2.7 stdlib; tarfile.extract() has no filter parameter)
 	- pypy3 <unfixed> (bug #1141531)
 	[trixie] - pypy3 <no-dsa> (Minor issue)
+	[bookworm] - pypy3 <postponed> (Minor issue)
+	[bullseye] - pypy3 <postponed> (Minor issue)
 	NOTE: https://mail.python.org/archives/list/security-announce@python.org/thread/TWZW2PC2AZOV6FENIHFSRC63OM7MBGSB/
 	NOTE: https://github.com/python/cpython/issues/151987
 	NOTE: https://github.com/python/cpython/pull/151988
 	NOTE: https://github.com/python/cpython/commit/7b57e8d51446297b8c7c482d224bc5f1938e4301 (3.15 branch)
 	NOTE: https://github.com/python/cpython/commit/5e0ef3f1afe892e4f64eb83368db57ac4c40cba0 (3.14 branch)
 	NOTE: https://github.com/python/cpython/commit/eee3ddf0ca10283cc7fea724aae9cd8665f8d15e (3.13 branch)
+	NOTE: Same code situation as with CVE-2025-4435.
 CVE-2026-49877 (Improper Authorization vulnerability in Apache ActiveMQ.  An authentic ...)
 	- activemq <unfixed> (bug #1141385)
 	NOTE: https://lists.apache.org/thread/w82vtc3q02j5ot94tnyy1197y3wb98hl



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cf0b36ff7e7fa5cc90ad136db01125b78392d169

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cf0b36ff7e7fa5cc90ad136db01125b78392d169
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260713/20e56e45/attachment.htm>


More information about the debian-security-tracker-commits mailing list