CVE-2026-3087

If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems. Only Windows is affected by this vulnerability.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha2:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha3:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha4:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha5:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha6:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha7:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha8:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

05 Jun 2026, 00:25

Type Values Removed Values Added
References () https://github.com/python/cpython/commit/65b255416ae217bf0e22085be3c1976cea18bd8c - () https://github.com/python/cpython/commit/65b255416ae217bf0e22085be3c1976cea18bd8c - Patch
References () https://github.com/python/cpython/commit/8e13025747e1ca72e86d1f35637123f9c306f0cb - () https://github.com/python/cpython/commit/8e13025747e1ca72e86d1f35637123f9c306f0cb - Patch
References () https://github.com/python/cpython/commit/8ee6aff14054b37b53e47194a2fa313e98163c94 - () https://github.com/python/cpython/commit/8ee6aff14054b37b53e47194a2fa313e98163c94 - Patch
References () https://github.com/python/cpython/commit/ba0aca3bffce431fe2fbd53ca4cd6a717a2e2c19 - () https://github.com/python/cpython/commit/ba0aca3bffce431fe2fbd53ca4cd6a717a2e2c19 - Patch
CPE cpe:2.3:a:python:python:3.15.0:alpha_4:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha_8:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha_7:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha_1:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha_6:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha_3:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha_2:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha_5:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha4:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha7:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha6:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha8:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha3:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha2:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha5:*:*:*:*:*:*

04 Jun 2026, 15:16

Type Values Removed Values Added
References
  • () https://github.com/python/cpython/commit/65b255416ae217bf0e22085be3c1976cea18bd8c -
  • () https://github.com/python/cpython/commit/8e13025747e1ca72e86d1f35637123f9c306f0cb -
  • () https://github.com/python/cpython/commit/8ee6aff14054b37b53e47194a2fa313e98163c94 -
  • () https://github.com/python/cpython/commit/ba0aca3bffce431fe2fbd53ca4cd6a717a2e2c19 -

13 May 2026, 16:27

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
References () https://github.com/python/cpython/commit/ab5ef98af693bded74a738570e81ea70abef2840 - () https://github.com/python/cpython/commit/ab5ef98af693bded74a738570e81ea70abef2840 - Patch
References () https://github.com/python/cpython/commit/b01e594fbe754a960212f908d047294e880b52fd - () https://github.com/python/cpython/commit/b01e594fbe754a960212f908d047294e880b52fd - Patch
References () https://github.com/python/cpython/commit/fc829e88753858c8ac669594bf0093f44948c0f4 - () https://github.com/python/cpython/commit/fc829e88753858c8ac669594bf0093f44948c0f4 - Patch
References () https://github.com/python/cpython/issues/146581 - () https://github.com/python/cpython/issues/146581 - Exploit, Issue Tracking, Patch, Vendor Advisory
References () https://github.com/python/cpython/pull/146591 - () https://github.com/python/cpython/pull/146591 - Issue Tracking, Patch
References () https://mail.python.org/archives/list/security-announce@python.org/thread/X6FXE5C6KDKOVNX3EC3DWD5RUPFWOZA4/ - () https://mail.python.org/archives/list/security-announce@python.org/thread/X6FXE5C6KDKOVNX3EC3DWD5RUPFWOZA4/ - Mailing List, Vendor Advisory
References () http://www.openwall.com/lists/oss-security/2026/04/28/9 - () http://www.openwall.com/lists/oss-security/2026/04/28/9 - Mailing List, Third Party Advisory
CPE cpe:2.3:a:python:python:3.15.0:alpha_4:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha_1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha_3:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha_8:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha_5:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha_2:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha_7:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha_6:*:*:*:*:*:*
First Time Microsoft
Python
Microsoft windows
Python python

29 Apr 2026, 16:16

Type Values Removed Values Added
References
  • () https://github.com/python/cpython/commit/ab5ef98af693bded74a738570e81ea70abef2840 -
  • () https://github.com/python/cpython/commit/b01e594fbe754a960212f908d047294e880b52fd -
  • () https://github.com/python/cpython/commit/fc829e88753858c8ac669594bf0093f44948c0f4 -

28 Apr 2026, 06:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/04/28/9 -

27 Apr 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-27 21:16

Updated : 2026-06-17 10:43


NVD link : CVE-2026-3087

Mitre link : CVE-2026-3087

CVE.ORG link : CVE-2026-3087


JSON object : View

Products Affected

microsoft

  • windows

python

  • python
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')