CVE-2026-3479

ADVISORY - nist

Summary

DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.

pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.

EPSS Score: 0.00014 (0.026)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

ADVISORY - redhat

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')


Docker

CREATED

UPDATED

ADVISORY ID

CVE-2026-3479

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY
PackageTypeOS NameOS VersionAffected RangesFix Versions
pythondhi--<3.13.133.13.13
alpine/python-3.10apkalpine3.23<3.13.133.13.13
alpine/python-3.10apkalpine3.23>=3.14.0-alpha1,<3.14.43.14.4
alpine/python-3.10apkalpine3.23>=3.15.0-alpha1,<3.15.0-alpha83.15.0-alpha8
alpine/python-3.11apkalpine3.23<3.13.133.13.13
alpine/python-3.11apkalpine3.23>=3.14.0-alpha1,<3.14.43.14.4
alpine/python-3.11apkalpine3.23>=3.15.0-alpha1,<3.15.0-alpha83.15.0-alpha8
alpine/python-3.12apkalpine3.23<3.13.133.13.13
alpine/python-3.12apkalpine3.23>=3.14.0-alpha1,<3.14.43.14.4
alpine/python-3.12apkalpine3.23>=3.15.0-alpha1,<3.15.0-alpha83.15.0-alpha8
alpine/python-3.13apkalpine3.23<3.13.133.13.13
alpine/python-3.13apkalpine3.23>=3.14.0-alpha1,<3.14.43.14.4
alpine/python-3.13apkalpine3.23>=3.15.0-alpha1,<3.15.0-alpha83.15.0-alpha8
alpine/python-3.14apkalpine3.23<3.13.133.13.13
alpine/python-3.14apkalpine3.23>=3.14.0-alpha1,<3.14.43.14.4
alpine/python-3.14apkalpine3.23>=3.15.0-alpha1,<3.15.0-alpha83.15.0-alpha8
pythondhi-->=3.14.0-alpha1,<3.14.43.14.4
pythondhi-->=3.15.0-alpha1,<3.15.0-alpha83.15.0-alpha8

Severity and metrics

No CVSS data available from this advisory.

NIST

CREATED

UPDATED

ADVISORY IDCVE-2026-3479
EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
RATING UNAVAILABLE FROM ADVISORY

Debian

CREATED

UPDATED

ADVISORY IDCVE-2026-3479
EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Alow

Ubuntu

CREATED

UPDATED

ADVISORY IDCVE-2026-3479
EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Amedium

Bitnami

CREATED

UPDATED

ADVISORY ID

BIT-libpython-2026-3479

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

2.1low

Bitnami

CREATED

UPDATED

ADVISORY ID

BIT-python-2026-3479

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

2.1low

Bitnami

CREATED

UPDATED

ADVISORY ID

BIT-python-min-2026-3479

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

2.1low

Red Hat

CREATED

UPDATED

ADVISORY IDCVE-2026-3479
EXPLOITABILITY SCORE

1.8

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

3.3low

Chainguard

CREATED

UPDATED

ADVISORY ID

CGA-g3hc-7hgr-hfv4

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY

minimos

CREATED

UPDATED

ADVISORY ID

MINI-7q7x-rxp3-2ppf

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY

minimos

CREATED

UPDATED

ADVISORY ID

MINI-8cv8-pf76-4gj2

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY

minimos

CREATED

UPDATED

ADVISORY ID

MINI-c8r3-rcw9-8mq2

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY

minimos

CREATED

UPDATED

ADVISORY ID

MINI-fvg5-6r76-6g9x

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY

minimos

CREATED

UPDATED

ADVISORY ID

MINI-j2cp-79jc-95mq

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY