Metrics
Affected Vendors & Products
Tue, 07 Apr 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 07 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals. | DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model. pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals. |
| Metrics |
cvssV4_0
|
cvssV4_0
|
Fri, 20 Mar 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Thu, 19 Mar 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 19 Mar 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Python
Python cpython |
|
| Vendors & Products |
Python
Python cpython |
Wed, 18 Mar 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-22 | |
| Metrics |
ssvc
|
Wed, 18 Mar 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals. | |
| Title | pkgutil.get_data() does not enforce documented restrictions | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: PSF
Published: 2026-03-18T18:13:42.288Z
Updated: 2026-04-07T22:01:35.724Z
Reserved: 2026-03-03T14:18:35.394Z
Link: CVE-2026-3479
Updated: 2026-03-18T18:49:24.573Z
Status : Awaiting Analysis
Published: 2026-03-18T19:16:06.810
Modified: 2026-04-07T18:16:46.740
Link: CVE-2026-3479