CVE-2026-3087
Last modified
CVE-2026-3087 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems. Only Windows is affected by this vulnerability.. EPSS estimates a 0.55% chance of exploitation in the next 30 days.
Description
If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems. Only Windows is affected by this vulnerability.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Python | Python | <= 3.14.4 | — |
| Python | Python | 3.15.0 | Alpha1 |
References
- https://github.com/python/cpython/issues/146581Exploit, Issue Tracking, Patch, Vendor Advisory
- https://github.com/python/cpython/pull/146591Issue Tracking, Patch
- https://mail.python.org/archives/list/security-announce@python.org/thread/X6FXE5C6KDKOVNX3EC3DWD5RUPFWOZA4/Mailing List, Vendor Advisory
- https://www.openwall.com/lists/oss-security/2026/04/28/9Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2026-3087?
How severe is CVE-2026-3087?
How do I fix CVE-2026-3087?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-30864Combodo iTop is a web-based IT service management tool. Prio…8.9
- CVE-2026-30865Combodo iTop is a web based IT service management tool. Prio…7.1
- CVE-2026-30866Combodo iTop is a web based IT service management tool. Prio…7.5
- CVE-2026-30867CocoaMQTT is a MQTT 5.0 client library for iOS and macOS wri…6.5
- CVE-2026-30868OPNsense is a FreeBSD based firewall and routing platform. P…8.1
- CVE-2026-30869SiYuan is a personal knowledge management system. Prior to 3…9.8
- CVE-2026-30870PowerSync Service is the server-side component of the PowerS…6.5
- CVE-2026-30871OpenWrt Project is a Linux operating system targeting embedd…9.8
- CVE-2026-30872OpenWrt Project is a Linux operating system targeting embedd…9.8
- CVE-2026-30873OpenWrt Project is a Linux operating system targeting embedd…4.9
- CVE-2026-30874OpenWrt Project is a Linux operating system targeting embedd…7.8
- CVE-2026-30875Chamilo LMS is a learning management system. Prior to versio…8.8
Are you affected by CVE-2026-3087?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
