{"id":"CVE-2019-20907","title":"In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.","summary":"In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-835"],"vendor":"python","product":"python","affected":["python >= 3.5.0, < 3.5.10","python >= 3.6.0, < 3.6.12","python >= 3.7.0, < 3.7.9","python >= 3.8.0, < 3.8.5","leap = 15.1","leap = 15.2","debian_linux = 9.0","fedora = 31","fedora = 32","ubuntu_linux = 12.04","ubuntu_linux = 14.04","ubuntu_linux = 16.04","ubuntu_linux = 18.04","ubuntu_linux = 20.04","active_iq_unified_manager >= 9.5","cloud_volumes_ontap_mediator","zfs_storage_appliance_kit = 8.8"],"patched":["python 3.8.5"],"published":"2020-07-13","updated":"2026-10-07","sourceUpdated":"2026-10-07T18:17:08.517","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2019-20907","references":[{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00051.html","label":"cve@mitre.org"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00052.html","label":"cve@mitre.org"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00053.html","label":"cve@mitre.org"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00056.html","label":"cve@mitre.org"},{"url":"https://bugs.python.org/issue39017","label":"cve@mitre.org"},{"url":"https://github.com/python/cpython/pull/21454","label":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","label":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-lts-announce/2020/11/msg00032.html","label":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36XI3EEQNMHGOZEI63Y7UV6XZRELYEAU/","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CAXHCY4V3LPAAJOBCJ26ISZ4NUXQXTUZ/","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CNHPQGSP2YM3JAUD2VAMPXTIUQTZ2M2U/","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CTUNTBJ3POHONQOTLEZC46POCIYYTAKZ/","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE4O3PNDNNOMSKHNUKZKD3NGHIFUFDPX/","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NTBKKOLFFNHG6CM4ACDX4APHSD5ZX5N4/","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OXI72HIHMXCQFWTULUXDG7VDA2BCYL4Y/","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PDKKRXLNVXRF6VGERZSR3OMQR5D5QI6I/","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TOGKLGTXZLHQQFBVCAPSUDA6DOOJFNRY/","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V3TALOUBYU2MQD4BPLRTDQUMBKGCAXUA/","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V53P2YOLEQH4J7S5QHXMKMZYFTVVMTMO/","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VT4AF72TJ2XNIKCR4WEBR7URBJJ4YZRD/","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YILCHHTNLH4GG4GSQBX2MZRKZBXOLCKE/","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YSL3XWVDMSMKO23HR74AJQ6VEM3C2NTS/","label":"cve@mitre.org"},{"url":"https://security.gentoo.org/glsa/202008-01","label":"cve@mitre.org"},{"url":"https://security.netapp.com/advisory/ntap-20200731-0002/","label":"cve@mitre.org"},{"url":"https://usn.ubuntu.com/4428-1/","label":"cve@mitre.org"},{"url":"https://www.oracle.com/security-alerts/cpujan2021.html","label":"cve@mitre.org"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00051.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00052.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00053.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00056.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://bugs.python.org/issue39017","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/python/cpython/pull/21454","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2020/11/msg00032.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36XI3EEQNMHGOZEI63Y7UV6XZRELYEAU/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CAXHCY4V3LPAAJOBCJ26ISZ4NUXQXTUZ/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CNHPQGSP2YM3JAUD2VAMPXTIUQTZ2M2U/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CTUNTBJ3POHONQOTLEZC46POCIYYTAKZ/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE4O3PNDNNOMSKHNUKZKD3NGHIFUFDPX/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NTBKKOLFFNHG6CM4ACDX4APHSD5ZX5N4/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OXI72HIHMXCQFWTULUXDG7VDA2BCYL4Y/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PDKKRXLNVXRF6VGERZSR3OMQR5D5QI6I/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TOGKLGTXZLHQQFBVCAPSUDA6DOOJFNRY/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V3TALOUBYU2MQD4BPLRTDQUMBKGCAXUA/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V53P2YOLEQH4J7S5QHXMKMZYFTVVMTMO/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VT4AF72TJ2XNIKCR4WEBR7URBJJ4YZRD/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YILCHHTNLH4GG4GSQBX2MZRKZBXOLCKE/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YSL3XWVDMSMKO23HR74AJQ6VEM3C2NTS/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.gentoo.org/glsa/202008-01","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20200731-0002/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://usn.ubuntu.com/4428-1/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujan2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","cve.org","score-dispute"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-10-07T17:58:36.334729Z"},"scores":{"nvd":7.5,"adp":5.5},"epss":0.06253,"epssPercentile":0.93381,"ingestedAt":"2026-10-07T18:42:20.872Z","slug":"CVE-2019-20907","body":"## Overview\n\nIn Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.\n\n## Affected\n\n- `python >= 3.5.0, < 3.5.10`\n- `python >= 3.6.0, < 3.6.12`\n- `python >= 3.7.0, < 3.7.9`\n- `python >= 3.8.0, < 3.8.5`\n- `leap = 15.1`\n- `leap = 15.2`\n- `debian_linux = 9.0`\n- `fedora = 31`\n- `fedora = 32`\n- `ubuntu_linux = 12.04`\n- `ubuntu_linux = 14.04`\n- `ubuntu_linux = 16.04`\n- `ubuntu_linux = 18.04`\n- `ubuntu_linux = 20.04`\n- `active_iq_unified_manager >= 9.5`\n- `cloud_volumes_ontap_mediator`\n- `zfs_storage_appliance_kit = 8.8`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `python 3.8.5`","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":41.3,"likelihood":1.3,"exploitation":0,"ransomware":0},"changes":[]}