Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 13 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft
Microsoft windows Python python |
|
| CPEs | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* cpe:2.3:a:python:python:3.15.0:alpha_1:*:*:*:*:*:* cpe:2.3:a:python:python:3.15.0:alpha_2:*:*:*:*:*:* cpe:2.3:a:python:python:3.15.0:alpha_3:*:*:*:*:*:* cpe:2.3:a:python:python:3.15.0:alpha_4:*:*:*:*:*:* cpe:2.3:a:python:python:3.15.0:alpha_5:*:*:*:*:*:* cpe:2.3:a:python:python:3.15.0:alpha_6:*:*:*:*:*:* cpe:2.3:a:python:python:3.15.0:alpha_7:*:*:*:*:*:* cpe:2.3:a:python:python:3.15.0:alpha_8:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Microsoft
Microsoft windows Python python |
|
| Metrics |
cvssV3_1
|
Wed, 29 Apr 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 28 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 28 Apr 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 28 Apr 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Python
Python cpython |
|
| Vendors & Products |
Python
Python cpython |
Mon, 27 Apr 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems. Only Windows is affected by this vulnerability. | |
| Title | shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: PSF
Published:
Updated: 2026-05-12T13:25:02.962Z
Reserved: 2026-02-23T23:14:46.433Z
Link: CVE-2026-3087
Updated: 2026-04-28T05:07:42.331Z
Status : Analyzed
Published: 2026-04-27T21:16:42.480
Modified: 2026-05-13T16:27:11.110
Link: CVE-2026-3087
No data.
OpenCVE Enrichment
Updated: 2026-04-28T13:00:15Z