FlawAtlas
Search the atlas
CVE-2026-11972 High

CVE-2026-11972

When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.

Exploit probability 0.4%
Published June 23, 2026
Required by Not available
Last source change August 5, 2026

02 / AFFECTED SOFTWARE

Affected packages

Bitnami python
Bitnami python-min
Bitnami libpython
Unknown Unknown

198 explicit affected versions

Unknown Unknown

247 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities BIT-libpython-2026-11972

When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.

View original source
Open Source Vulnerabilities BIT-python-2026-11972

When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.

View original source
Open Source Vulnerabilities BIT-python-min-2026-11972

When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.

View original source
Open Source Vulnerabilities CVE-2026-11972

When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.

View original source
Open Source Vulnerabilities PSF-2026-31

When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.

View original source

05 / REFERENCES

Further evidence