{"id":"AZL-89472","summary":"CVE-2026-7774 affecting package python3 for versions less than 3.12.9-13","details":"tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.","modified":"2026-09-08T17:33:11Z","published":"2026-06-04T16:16:42Z","upstream":["CVE-2026-7774"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-7774"}],"affected":[{"package":{"name":"python3","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/python3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.12.9-13"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-89472.json"}}],"schema_version":"1.9.0"}