[CVE-2026-11972] tarfile opened in streaming mode mishandles EOF
June 23, 2026
10:01 p.m.
There is a MEDIUM severity vulnerability affecting CPython.
When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly handle EOF, meaning an archive could be parsed in an infinite loop.
Please see the linked CVE ID for the latest information on affected versions:
52
Age (days ago)
52
Last active (days ago)
0 comments
1 participants
participants (1)
-
Seth Larson