If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems. Only Windows is affected by this vulnerability.
References
Configurations
Configuration 1 (hide)
| AND |
|
History
05 Jun 2026, 00:25
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/python/cpython/commit/65b255416ae217bf0e22085be3c1976cea18bd8c - Patch | |
| References | () https://github.com/python/cpython/commit/8e13025747e1ca72e86d1f35637123f9c306f0cb - Patch | |
| References | () https://github.com/python/cpython/commit/8ee6aff14054b37b53e47194a2fa313e98163c94 - Patch | |
| References | () https://github.com/python/cpython/commit/ba0aca3bffce431fe2fbd53ca4cd6a717a2e2c19 - Patch | |
| CPE | cpe:2.3:a:python:python:3.15.0:alpha_8:*:*:*:*:*:* cpe:2.3:a:python:python:3.15.0:alpha_7:*:*:*:*:*:* cpe:2.3:a:python:python:3.15.0:alpha_1:*:*:*:*:*:* cpe:2.3:a:python:python:3.15.0:alpha_6:*:*:*:*:*:* cpe:2.3:a:python:python:3.15.0:alpha_3:*:*:*:*:*:* cpe:2.3:a:python:python:3.15.0:alpha_2:*:*:*:*:*:* cpe:2.3:a:python:python:3.15.0:alpha_5:*:*:*:*:*:* |
cpe:2.3:a:python:python:3.15.0:alpha4:*:*:*:*:*:* cpe:2.3:a:python:python:3.15.0:alpha7:*:*:*:*:*:* cpe:2.3:a:python:python:3.15.0:alpha1:*:*:*:*:*:* cpe:2.3:a:python:python:3.15.0:alpha6:*:*:*:*:*:* cpe:2.3:a:python:python:3.15.0:alpha8:*:*:*:*:*:* cpe:2.3:a:python:python:3.15.0:alpha3:*:*:*:*:*:* cpe:2.3:a:python:python:3.15.0:alpha2:*:*:*:*:*:* cpe:2.3:a:python:python:3.15.0:alpha5:*:*:*:*:*:* |
04 Jun 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
13 May 2026, 16:27
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| References | () https://github.com/python/cpython/commit/ab5ef98af693bded74a738570e81ea70abef2840 - Patch | |
| References | () https://github.com/python/cpython/commit/b01e594fbe754a960212f908d047294e880b52fd - Patch | |
| References | () https://github.com/python/cpython/commit/fc829e88753858c8ac669594bf0093f44948c0f4 - Patch | |
| References | () https://github.com/python/cpython/issues/146581 - Exploit, Issue Tracking, Patch, Vendor Advisory | |
| References | () https://github.com/python/cpython/pull/146591 - Issue Tracking, Patch | |
| References | () https://mail.python.org/archives/list/security-announce@python.org/thread/X6FXE5C6KDKOVNX3EC3DWD5RUPFWOZA4/ - Mailing List, Vendor Advisory | |
| References | () http://www.openwall.com/lists/oss-security/2026/04/28/9 - Mailing List, Third Party Advisory | |
| CPE | cpe:2.3:a:python:python:3.15.0:alpha_4:*:*:*:*:*:* cpe:2.3:a:python:python:3.15.0:alpha_1:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:a:python:python:*:*:*:*:*:*:*:* cpe:2.3:a:python:python:3.15.0:alpha_3:*:*:*:*:*:* cpe:2.3:a:python:python:3.15.0:alpha_8:*:*:*:*:*:* cpe:2.3:a:python:python:3.15.0:alpha_5:*:*:*:*:*:* cpe:2.3:a:python:python:3.15.0:alpha_2:*:*:*:*:*:* cpe:2.3:a:python:python:3.15.0:alpha_7:*:*:*:*:*:* cpe:2.3:a:python:python:3.15.0:alpha_6:*:*:*:*:*:* |
|
| First Time |
Microsoft
Python Microsoft windows Python python |
29 Apr 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
28 Apr 2026, 06:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
27 Apr 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-27 21:16
Updated : 2026-06-17 10:43
NVD link : CVE-2026-3087
Mitre link : CVE-2026-3087
CVE.ORG link : CVE-2026-3087
JSON object : View
Products Affected
microsoft
- windows
python
- python
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
