CVE-2026-11972: Python Software Foundation Cpython

High severity, CVSS 8.2. EPSS: 0.7% chance of exploitation in the next 30 days.

When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.

Affected products

  • Python Software Foundation Cpython: before 3.10.21 (fixed in 3.10.21); from 3.11.0, before 3.11.16 (fixed in 3.11.16); from 3.12.0, before 3.12.14 (fixed in 3.12.14); from 3.13.0, before 3.13.15 (fixed in 3.13.15); from 3.14.0, before 3.14.7 (fixed in 3.14.7); from 3.15.0a1, before 3.15.0b4 (fixed in 3.15.0b4)

Published 2026-06-23. Last modified 2026-08-13.