Skip to content

CVE-2026-3479 on CTRL-OS 26.05

Aliases: CVE-2026-3479

Packages: python313

Status: Plausible, Resolved

Advisory Information

DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.

pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.

Updates

2026-07-21 16:55 CEST

Metadata changes:

  • Status for package python313: “Resolved” (634df81a6bde9521cc2c14bc512ba5b2a89ae13f)

2026-07-21 16:55 CEST

Metadata changes:

  • Status for package python314: “Resolved” (e5a825f3cb5cde6a9a655154e641c580acb641fc)

2026-07-21 16:55 CEST

Metadata changes:

  • Status for package python315: “Resolved” (51c6e5d2b4f5f5c7e3eb08a28cc7d76f36506ade)

2026-07-21 16:54 CEST

Metadata changes:

  • Status for package python311: “Plausible
  • Status for package python312: “Plausible
  • Status for package python313: “Plausible
  • Status for package python314: “Plausible
  • Status for package python315: “Plausible

2026-06-04 00:03 CEST

Metadata changes:

  • Status for package python311: “New
  • Status for package python312: “New
  • Status for package python313: “New
  • Status for package python314: “New
  • Status for package python315: “New

(Amended on: 2026-06-04 00:05 CEST)