Threats Tagged 'cve-2026-19672'
View all threats tagged with 'cve-2026-19672'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-19672'
Click on any threat for detailed analysis and mitigation recommendations
When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controlled size to pre-allocate memory, possibly resulting in memory exhaustion. Join the discussion | CVE Database V5 | 10/02/2026, 00:00:00 UTC Added: 08/25/2026, 15:27:40 UTC |
Red Hat has released a security update for Red Hat Hardened Images RPMs, specifically addressing multiple vulnerabilities in python3.13 packages. The update includes fixes for CVE-2026-15310, CVE-2026-15806, CVE-2026-19672, and CVE-2026-17084. The affected packages cover various python3.13 components for aarch64 and x86_64 architectures. The update is available and should be applied to mitigate the identified security issues. Join the discussion | GCVE Database | 09/08/2026, 17:00:11 UTC Added: 09/25/2026, 04:42:06 UTC |
CVE-2026-19672 is a directory traversal vulnerability in the Python tarfile module affecting POSIX platforms. The issue allows creation of empty directories outside the intended extraction destination when member names contain path components that leave and then return to the destination directory. This does not affect Windows due to path normalization. Only empty directories are created outside the destination; file contents remain inside. The vulnerability affects CPython versions before 3.16.0 and has a medium severity rating with a CVSS score of 6.3. Join the discussion | CVE Database V5 | 08/19/2026, 15:24:08 UTC Added: 08/19/2026, 15:37:44 UTC |
Showing 1 to 3 of 3 results