CVE-2026-11972: Python Software Foundation Cpython
High severity, CVSS 8.2. EPSS: 0.7% chance of exploitation in the next 30 days.
When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.
Affected products
- Python Software Foundation Cpython: before 3.10.21 (fixed in 3.10.21); from 3.11.0, before 3.11.16 (fixed in 3.11.16); from 3.12.0, before 3.12.14 (fixed in 3.12.14); from 3.13.0, before 3.13.15 (fixed in 3.13.15); from 3.14.0, before 3.14.7 (fixed in 3.14.7); from 3.15.0a1, before 3.15.0b4 (fixed in 3.15.0b4)
Published 2026-06-23. Last modified 2026-08-13.