Red Hat released Important security updates for python3.12 and python3.14 across RHEL 8, 9, and 10 to address CVE-2026-11940, a CPython tarfile extraction filter bypass that can let files escape the intended extraction directory. The flaw is a form of path traversal mapped to CWE-22, where specially crafted archive entries can write outside a restricted destination and potentially enable unauthorized file overwrite, file creation, or broader system impact. Updated packages include python3.12-3.12.14-1.el8_10, python3.12-3.12.14-1.el9_8, python3.12.14-1.el10_2, and python3.14.7-2.el10_2 for multiple architectures and channels.
The remediation has also propagated into downstream enterprise Linux ecosystems. Nessus plugin coverage shows Rocky Linux 9 and AlmaLinux 8 advisories tracking the same vulnerability through RLSA-2026:59009 and ALSA-2026:58971, respectively, affecting multiple Python 3.12 package variants such as libraries, development files, and related components. The scanner entries note the vulnerability was published on 2026-06-23 and report no known public exploits, but organizations running Python archive extraction workflows on affected Red Hat-derived systems are being directed to deploy the vendor package updates.

See affected versions and whether adversaries are exploiting it.
21 events from the most recent confirmed update back to the earliest known activity.
Red Hat published RHSA-2026:63024 for RHEL 10, updating affected python3.12 and related Python packages to remediate CVE-2026-11940. The Important-rated advisory was published on September 3, 2026; the notice reported no known exploits.
Red Hat published RHSA-2026:62809 for RHEL 9 to remediate CVE-2026-11940 in affected python3.12 packages, including development, library, and Tkinter components. The Important-rated advisory was published on September 2, 2026; no known exploits were available.
Miracle Linux published advisory AXSA-2026-1673 for Miracle Linux 9, updating Python 3.14 standard and free-threading package variants to remediate CVE-2026-11940. The advisory covered runtime, debug, development, IDLE, library, test, and Tkinter packages and reported no known exploits.
Miracle Linux published advisory AXSA-2026-1655 for Miracle Linux 8, updating affected Python 3.12 runtime, development, debugging, IDLE, Tkinter, test, and related packages to remediate CVE-2026-11940. The Tenable plugin states that no known public exploits were available.
Miracle Linux published advisory AXSA-2026-1652 for Miracle Linux 8, updating affected platform-python and related Python 3 packages to remediate CVE-2026-11940. The plugin reported no known public exploits at publication.
Oracle Linux published ELSA-2026-59009 for Oracle Linux 9, updating affected Python 3.12 packages including debug, development, idle, libraries, test, and tkinter variants to remediate CVE-2026-11940. The plugin reported no known public exploits.
Oracle Linux published ELSA-2026-58901 for Oracle Linux 9, updating Python 3.14 and related standard and free-threading package variants to remediate CVE-2026-11940. The advisory stated that no known exploits were available.
Rocky Linux published RLSA-2026-58902 for Rocky Linux 10, updating Python 3.12-related packages to remediate CVE-2026-11940. The advisory covers python3 and related libraries, development, debug, test, and tkinter packages; it reported no known exploits at publication.
Tenable's Rocky Linux plugin records patch publication for RLSA-2026-59009 affecting Rocky Linux 9 python3.12-related packages for CVE-2026-11940. The plugin also states that no known exploits were available.
AlmaLinux published ALSA-2026:59009 to remediate CVE-2026-11940 in AlmaLinux 9 Python 3.12 packages across affected repositories. The Tenable plugin records the patch publication date as 2026-08-24 and states that no known public exploits were available.
Oracle Linux published ELSA-2026-58971 for Oracle Linux 8, updating affected Python 3.12 package variants to remediate CVE-2026-11940. The Tenable plugin states that no known exploits were available.
Tenable's AlmaLinux plugin records patch publication for ALSA-2026:58971, covering AlmaLinux 8 Python 3.12 packages affected by CVE-2026-11940. The plugin notes no known exploits were available at that time.
Red Hat published RHSA-2026:59009 for RHEL 9, making updated python3.12 packages version 3.12.14-1.el9_8 available to remediate CVE-2026-11940. The Important-rated advisory covered multiple architectures and related extended support channels.
Red Hat published RHSA-2026:58928 for RHEL 10, releasing python3.14 packages version 3.14.7-2.el10_2 for CVE-2026-11940. The advisory marked the issue Important and covered standard and CodeReady Linux Builder channels across several architectures.
Red Hat published RHSA-2026:58902 for RHEL 10, providing python3.12 version 3.12.14-1.el10_2 to fix CVE-2026-11940. The Important-rated update applied across multiple architectures and extended support channels.
Red Hat published RHSA-2026:58971 for RHEL 8, releasing updated python3.12 packages version 3.12.14-1.el8_10 to address CVE-2026-11940. The Important-rated update covered multiple architectures and related CodeReady Linux Builder and Extended Life Cycle channels.
Tencent published TSSA-2026:0914 for TencentOS Server 3 to remediate CVE-2026-11940. Tenable records the patch as published on August 18, 2026, and states that no known exploits were available.
Fedora published advisory FEDORA-2026-7de2b1cfc5 for Fedora 43 python3.12 packages, addressing CVE-2026-11940 alongside CVE-2026-3276 and CVE-2026-7210. The notice reported no known exploits for CVE-2026-11940.
Tenable's AlmaLinux plugin records patch publication for ALSA-2026:58902, covering AlmaLinux 10 Python 3.12-related packages affected by CVE-2026-11940. The plugin notes the patch was published on 2026-08-24 and that no known exploits were available.
The vulnerability CVE-2026-11940 was published as a CPython tarfile extraction filter bypass that can let files escape the intended extraction directory. Tenable plugin metadata ties the issue to CWE-22 path traversal.
Red Hat's Bug 2491848 record states that CVE-2026-11940 was addressed for Red Hat Enterprise Linux 9 through advisory RHSA-2026:58901. The record describes the flaw as an incomplete fix for CVE-2025-4330 affecting CPython tarfile extraction filters.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
22 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.