---
id: CVE-2026-11940
title: "tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.\_ \nThe extraction fallback validated the symlink at it's…"
summary: "tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.\_ \nThe extraction fallback validated the symlink at it's…"
severity: high
cwe:
  - CWE-22
  - CWE-59
published: '2026-06-23'
updated: '2026-08-06'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-11940'
references:
  - url: >-
      https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f
    label: cna@python.org
  - url: >-
      https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df
    label: cna@python.org
  - url: >-
      https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde
    label: cna@python.org
  - url: >-
      https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c
    label: cna@python.org
  - url: >-
      https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9
    label: cna@python.org
  - url: >-
      https://github.com/python/cpython/commit/e5fdbd8d5aa923bd9111b112ea73bd6ec7c47877
    label: cna@python.org
  - url: 'https://github.com/python/cpython/issues/151558'
    label: cna@python.org
  - url: 'https://github.com/python/cpython/pull/151559'
    label: cna@python.org
  - url: >-
      https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/
    label: cna@python.org
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-11940.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-11940'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2491848'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-11940'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-11940'
  - url: 'https://access.redhat.com/errata/RHSA-2026:63024'
  - url: 'https://access.redhat.com/errata/RHSA-2026:58902'
  - url: 'https://access.redhat.com/errata/RHSA-2026:58928'
  - url: 'https://access.redhat.com/errata/RHSA-2026:56219'
  - url: 'https://access.redhat.com/errata/RHSA-2026:58971'
  - url: 'https://access.redhat.com/errata/RHSA-2026:64816'
  - url: 'https://access.redhat.com/errata/RHSA-2026:64806'
  - url: 'https://access.redhat.com/errata/RHSA-2026:62809'
  - url: 'https://access.redhat.com/errata/RHSA-2026:63117'
  - url: 'https://access.redhat.com/errata/RHSA-2026:54268'
  - url: 'https://access.redhat.com/errata/RHSA-2026:59009'
  - url: 'https://access.redhat.com/errata/RHSA-2026:58901'
  - url: 'https://access.redhat.com/errata/RHSA-2026:54760'
  - url: 'https://access.redhat.com/errata/RHSA-2026:38018'
  - url: 'https://access.redhat.com/errata/RHSA-2026:38017'
  - url: 'https://access.redhat.com/errata/RHSA-2026:38090'
  - url: 'https://access.redhat.com/errata/RHSA-2026:38091'
  - url: 'https://access.redhat.com/errata/RHSA-2026:54534'
  - url: 'https://access.redhat.com/errata/RHSA-2026:58981'
  - url: 'https://access.redhat.com/errata/RHSA-2026:66018'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
epss: 0.0075
epssPercentile: 0.53505
ingestedAt: '2026-08-06T19:02:50.068Z'
vendor: Red Hat
product: Red Hat Enterprise Linux 8
affected:
  - enterprise_linux 8
  - enterprise_linux 9
  - enterprise_linux_appstream_eus_v_10_0
  - enterprise_linux_appstream_v_10
  - enterprise_linux_appstream_v_8
  - enterprise_linux_appstream_aus_v_8_6
  - enterprise_linux_appstream_eus_extension_v_8_6
  - enterprise_linux_appstream_e4s_v_8_8
  - enterprise_linux_appstream_tus_v_8_8
  - enterprise_linux_appstream_e4s_v_9_4
  - enterprise_linux_appstream_eus_v_9_6
  - enterprise_linux_appstream_v_9
  - enterprise_linux_baseos_eus_v_10_0
  - enterprise_linux_baseos_v_10
  - enterprise_linux_baseos_v_8
  - enterprise_linux_baseos_aus_v_8_6
  - enterprise_linux_baseos_eus_extension_v_8_6
  - enterprise_linux_baseos_e4s_v_8_8
  - enterprise_linux_baseos_tus_v_8_8
  - enterprise_linux_baseos_v_9
  - enterprise_linux_codeready_linux_builder_eus_v_10_0
  - enterprise_linux_codeready_linux_builder_v_10
  - enterprise_linux_crb_v_8
  - codeready_linux_builder_eus_v_9_6
  - enterprise_linux_codeready_linux_builder_v_9
  - discovery 2
  - hardened_images
  - update_infrastructure 5
patched:
  - enterprise_linux_appstream_eus_v_10_0
  - enterprise_linux_appstream_v_10
  - enterprise_linux_appstream_v_8
  - enterprise_linux_appstream_aus_v_8_6
  - enterprise_linux_appstream_eus_extension_v_8_6
  - enterprise_linux_appstream_e4s_v_8_8
  - enterprise_linux_appstream_tus_v_8_8
  - enterprise_linux_appstream_e4s_v_9_4
  - enterprise_linux_appstream_eus_v_9_6
  - enterprise_linux_appstream_v_9
  - enterprise_linux_baseos_eus_v_10_0
  - enterprise_linux_baseos_v_10
  - enterprise_linux_baseos_v_8
  - enterprise_linux_baseos_aus_v_8_6
  - enterprise_linux_baseos_eus_extension_v_8_6
  - enterprise_linux_baseos_e4s_v_8_8
  - enterprise_linux_baseos_tus_v_8_8
  - enterprise_linux_baseos_v_9
  - enterprise_linux_codeready_linux_builder_eus_v_10_0
  - enterprise_linux_codeready_linux_builder_v_10
  - enterprise_linux_crb_v_8
  - codeready_linux_builder_eus_v_9_6
  - enterprise_linux_codeready_linux_builder_v_9
  - discovery 2
  - hardened_images
  - update_infrastructure 5
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N'
cvssSource: vendor
---

## Overview

tarfile.extractall() with the 'data' or 'tar'
 filter could be bypassed by a crafted archive where a hardlink 
references a symlink stored at a deeper name than the hardlink itself.  
The extraction fallback validated the symlink at it's archived location 
but recreated it at the hardlink's shallower
path, letting a relative
 target the filter judged contained escape the destination directory.  
This allowed a malicious tar archive to create a symlink pointing 
outside the destination, enabling out-of-destination file reads or 
writes. This was an incomplete fix of CVE-2025-4330.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:63024** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0), Red Hat Enterprise Linux BaseOS EUS (v. 10.0), Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0) · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63024)
- **RHSA-2026:58902** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux BaseOS (v. 10), Red Hat Enterprise Linux CodeReady Linux Builder (v. 10) · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:58902)
- **RHSA-2026:58928** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux CodeReady Linux Builder (v. 10) · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:58928)
- **RHSA-2026:56219** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8), Red Hat Enterprise Linux BaseOS (v. 8) · released 2026-08-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:56219)
- **RHSA-2026:58971** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8), Red Hat Enterprise Linux CRB (v. 8) · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:58971)
- **RHSA-2026:64816** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream AUS (v.8.6), Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6), Red Hat Enterprise Linux BaseOS AUS (v.8.6), Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6) · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:64816)
- **RHSA-2026:64806** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.8.8), Red Hat Enterprise Linux AppStream TUS (v.8.8), Red Hat Enterprise Linux BaseOS E4S (v.8.8), Red Hat Enterprise Linux BaseOS TUS (v.8.8) · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:64806)
- **RHSA-2026:62809** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.4) · released 2026-09-02 · [advisory](https://access.redhat.com/errata/RHSA-2026:62809)
- **RHSA-2026:63117** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6), Red Hat CodeReady Linux Builder EUS (v.9.6) · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63117)
- **RHSA-2026:54268** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux BaseOS (v. 9), Red Hat Enterprise Linux CodeReady Linux Builder (v. 9) · released 2026-08-12 · [advisory](https://access.redhat.com/errata/RHSA-2026:54268)
- **RHSA-2026:59009** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux CodeReady Linux Builder (v. 9) · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:59009)
- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 · no fix planned: Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 · updated 2026-09-10 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-11940.json)
