Skip to content

Conversation

@ambv
Copy link
Contributor

@ambvambv commented Jun 3, 2025

Addresses CVEs 2024-12718, 2025-4138, 2025-4330, and 2025-4517.

(cherry picked from commit 3612d8f)


📚 Documentation preview 📚: https://cpython-previews--135065.org.readthedocs.build/

…path(strict='allow_missing')` (python#135037) Addresses CVEs 2024-12718, 2025-4138, 2025-4330, and 2025-4517. Signed-off-by: Łukasz Langa <[email protected]> Co-authored-by: Petr Viktorin <[email protected]> Co-authored-by: Seth Michael Larson <[email protected]> Co-authored-by: Adam Turner <[email protected]> Co-authored-by: Serhiy Storchaka <[email protected]> (cherry picked from commit 3612d8f)
@ambvambv requested a review from ethanfurman as a code ownerJune 3, 2025 11:13
@ambvambv changed the title gh-135034: Normalize link targets in tarfile, add os.path.realpath(strict='allow_missing') (gh-135037)[3.14] gh-135034: Normalize link targets in tarfile, add os.path.realpath(strict='allow_missing') (gh-135037)Jun 3, 2025
@ambvambv merged commit 9e0ac76 into python:3.14Jun 3, 2025
44 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@ambv