DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-65p2-g7f2-qqrm

Package

python-3.12

Component

python-3.12

Latest update

Not affected

Aliases

Severity

Unknown
Eliminate CVEs with Chainguard hardened images

Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.

Start for free

References

  • https://nvd.nist.gov/vuln/detail/CVE-2007-4559

Updates

Status

Not affected

Justification

Vulnerable code not present

Impact

Upon further investigation, we have determined that this is not a security issue in the Python package itself. It's still possible to misuse the Python standard library, such as by supplying untrusted data to the tar extraction functions, in which case a vulnerability should be identified in the caller code.

Status

Affected

Impact

Users should upgrade to version 3.12.0_beta1-r0 or later and set the filter parameter to 'data' when calling TarFile.extract and TarFile.extractall methods. For more information, see https://peps.python.org/pep-0706/.

Status

Not affected

Justification

Vulnerable code not present

Impact

The upstream issue has been closed, deeming this to be expected behavior, not a security issue. See https://bugs.python.org/issue1044.


The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.