CVE-2026-3479 on CTRL-OS 26.05
Aliases: CVE-2026-3479
Packages: python313
Status: Plausible, Resolved
Advisory Information
DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.
pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.
Updates
2026-07-21 16:55 CEST
Metadata changes:
- Status for package
python313: “Resolved” (634df81a6bde9521cc2c14bc512ba5b2a89ae13f)
2026-07-21 16:55 CEST
Metadata changes:
- Status for package
python314: “Resolved” (e5a825f3cb5cde6a9a655154e641c580acb641fc)
2026-07-21 16:55 CEST
Metadata changes:
- Status for package
python315: “Resolved” (51c6e5d2b4f5f5c7e3eb08a28cc7d76f36506ade)
2026-07-21 16:54 CEST
Metadata changes:
- Status for package
python311: “Plausible” - Status for package
python312: “Plausible” - Status for package
python313: “Plausible” - Status for package
python314: “Plausible” - Status for package
python315: “Plausible”
2026-06-04 00:03 CEST
Metadata changes:
- Status for package
python311: “New” - Status for package
python312: “New” - Status for package
python313: “New” - Status for package
python314: “New” - Status for package
python315: “New”
(Amended on: 2026-06-04 00:05 CEST)