Title: Multiple tarfile extraction filter bypasses (`filter="tar"`/`filter="data"`) · Issue #135034 · python/cpython · GitHub
Open Graph Title: Multiple tarfile extraction filter bypasses (`filter="tar"`/`filter="data"`) · Issue #135034 · python/cpython
X Title: Multiple tarfile extraction filter bypasses (`filter="tar"`/`filter="data"`) · Issue #135034 · python/cpython
Description: Bug description: Public issue for fixing CVE-2025-4517, CVE-2025-4330, CVE-2025-4138, and CVE-2024-12718. See full advisory on security-announce. [edit @encukou]: Also addresses CVE-2025-4435. Sorry for leaving that out of the commit mes...
Open Graph Description: Bug description: Public issue for fixing CVE-2025-4517, CVE-2025-4330, CVE-2025-4138, and CVE-2024-12718. See full advisory on security-announce. [edit @encukou]: Also addresses CVE-2025-4435. Sorr...
X Description: Bug description: Public issue for fixing CVE-2025-4517, CVE-2025-4330, CVE-2025-4138, and CVE-2024-12718. See full advisory on security-announce. [edit @encukou]: Also addresses CVE-2025-4435. Sorr...
Opengraph URL: https://github.com/python/cpython/issues/135034
X: @github
Domain: github.com
{"@context":"https://schema.org","@type":"DiscussionForumPosting","headline":"Multiple tarfile extraction filter bypasses (`filter=\"tar\"`/`filter=\"data\"`)","articleBody":"### Bug description:\n\nPublic issue for fixing CVE-2025-4517, CVE-2025-4330, CVE-2025-4138, and CVE-2024-12718. [See full advisory on security-announce](https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/).\n\n[edit @encukou]: Also addresses CVE-2025-4435. Sorry for leaving that out of the commit messages.\n\n### CPython versions tested on:\n\nCPython main branch\n\n### Operating systems tested on:\n\n_No response_\n\n\u003c!-- gh-linked-prs --\u003e\n### Linked PRs\n* gh-135037\n* gh-135064\n* gh-135065\n* gh-135066\n* gh-135068\n* gh-135070\n* gh-135084\n* gh-135093\n\u003c!-- /gh-linked-prs --\u003e\n","author":{"url":"https://github.com/sethmlarson","@type":"Person","name":"sethmlarson"},"datePublished":"2025-06-02T15:57:00.000Z","interactionStatistic":{"@type":"InteractionCounter","interactionType":"https://schema.org/CommentAction","userInteractionCount":0},"url":"https://github.com/135034/cpython/issues/135034"}
| route-pattern | /_view_fragments/issues/show/:user_id/:repository/:id/issue_layout(.:format) |
| route-controller | voltron_issues_fragments |
| route-action | issue_layout |
| fetch-nonce | v2:f291c515-a9d4-45f9-7a63-e10f314eb6bf |
| current-catalog-service-hash | 81bb79d38c15960b92d99bca9288a9108c7a47b18f2423d0f6438c5b7bcd2114 |
| request-id | 87B2:20E038:7221:90AB:696B30E7 |
| html-safe-nonce | 8cd47a11449df31f53911ba2708cd51d4e9f3adbec0244327f8013379d7e2465 |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiI4N0IyOjIwRTAzODo3MjIxOjkwQUI6Njk2QjMwRTciLCJ2aXNpdG9yX2lkIjoiODkzNTcxMjc5MDA0Mjg0OTUxMSIsInJlZ2lvbl9lZGdlIjoiaWFkIiwicmVnaW9uX3JlbmRlciI6ImlhZCJ9 |
| visitor-hmac | db0b97f7e3e458f04e0bcbbf0b5f5011178c0e811cbf137b4df12924fc1b6664 |
| hovercard-subject-tag | issue:3110750130 |
| github-keyboard-shortcuts | repository,issues,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/_view_fragments/issues/show/python/cpython/135034/issue_layout |
| twitter:image | https://opengraph.githubassets.com/691b422bbe8b15f1937d549349ddca7b3e7c6368eef4a54d89ab79246c366b29/python/cpython/issues/135034 |
| twitter:card | summary_large_image |
| og:image | https://opengraph.githubassets.com/691b422bbe8b15f1937d549349ddca7b3e7c6368eef4a54d89ab79246c366b29/python/cpython/issues/135034 |
| og:image:alt | Bug description: Public issue for fixing CVE-2025-4517, CVE-2025-4330, CVE-2025-4138, and CVE-2024-12718. See full advisory on security-announce. [edit @encukou]: Also addresses CVE-2025-4435. Sorr... |
| og:image:width | 1200 |
| og:image:height | 600 |
| og:site_name | GitHub |
| og:type | object |
| og:author:username | sethmlarson |
| hostname | github.com |
| expected-hostname | github.com |
| None | 5f99f7c1d70f01da5b93e5ca90303359738944d8ab470e396496262c66e60b8d |
| turbo-cache-control | no-preview |
| go-import | github.com/python/cpython git https://github.com/python/cpython.git |
| octolytics-dimension-user_id | 1525981 |
| octolytics-dimension-user_login | python |
| octolytics-dimension-repository_id | 81598961 |
| octolytics-dimension-repository_nwo | python/cpython |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | false |
| octolytics-dimension-repository_network_root_id | 81598961 |
| octolytics-dimension-repository_network_root_nwo | python/cpython |
| turbo-body-classes | logged-out env-production page-responsive |
| disable-turbo | false |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | 82560a55c6b2054555076f46e683151ee28a19bc |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width