← All credits
Petr Viktorin (https://github.com/encukou)
13 vulnerability records and advisories credit this contributor.
CVE-2026-87910
tarfile hardlink fallback ignores custom extraction filter rejection via None
CVE-2026-82049
tarfile extraction filters allow file modification and content disclosure via hard link to symlink
CVE-2026-17084
stringprep.map_table_b2() deviates from RFC 3454 Table B.2
CVE-2026-15310
zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits
CVE-2026-12345
Race condition in tempfile.TemporaryDirectory cleanup allows deleting files outside the temporary directory
CVE-2026-19672
tarfile extraction filter bypass allows creation of directories outside the destination
CVE-2026-0864
Configuration Injection via Carriage Return (\r) in write() method
CVE-2026-7774
tarfile.data_filter path traversal bypass allows writing outside the extraction directory
CVE-2026-6879
Quadratic Behavior in xml.etree.ElementPath Index Predicates
CVE-2026-4360
Tarfile.extract() doesn't fully respect filter parameter