CVE-2026-23949: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-23949 is a Zip Slip path traversal vulnerability (CWE-22) in the jaraco.context.tarball() function of the jaraco.context Python package. It affects versions 5.2.0 through prior to 6.1.0, and also impacts setuptools via its vendored copy at setuptools._vendor.jaraco.context. The vulnerability was disclosed on January 13, 2026, via a GitHub Security Advisory, with CVE assignment on January 20, 2026. It carries a CVSS v3.1 base score of 8.6 (High) (GitHub Advisory, Red Hat Bugzilla).

Technical details

The root cause is improper path sanitization in the strip_first_component filter function (CWE-22), which is used by tarball() to strip the leading directory component from tar archive member paths. The filter splits the path on the first / and returns the remainder, but does not validate or reject ../ sequences — so a crafted path like dummy_dir/../../etc/passwd becomes ../../etc/passwd after stripping, enabling writes outside the intended extraction directory. On Python 3.12+, this custom filter also silently overrides the native tarfile security hardening (the data_filter), creating a false sense of sanitization. The vulnerability additionally supports nested tarball attacks: a member named dummy_dir/inner.tar.gz containing an inner archive with traversal paths (e.g., dummy_dir/../../config/.env) will also have its paths translated unsafely. A public proof-of-concept is included in the GitHub Security Advisory (GitHub Advisory, Patch Commit).

Impact

Successful exploitation allows an unauthenticated remote attacker to write arbitrary files to locations outside the intended extraction directory on the target filesystem. This can result in overwriting sensitive system files (e.g., /etc/passwd, .env configuration files), planting malicious content in critical directories, or enabling privilege escalation if writable paths are accessible to privileged processes. The scope is marked as Changed in CVSS, reflecting that the impact extends beyond the vulnerable component itself; confidentiality impact is rated High due to the potential for sensitive file exposure or manipulation. In supply-chain scenarios — where popular packages download and extract remote tarballs using this library — the exploitability and blast radius are significantly elevated (GitHub Advisory).

Exploitability

A public proof-of-concept exploit script is included in the GitHub Security Advisory, demonstrating successful path traversal on Python versions 3.11 and earlier on Debian GNU/Linux 12. There is no evidence of in-the-wild exploitation or threat actor attribution at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.043% (0.000430), indicating low current exploitation probability. The vulnerability is detectable by Nessus and Qualys scanners (GitHub Advisory, Feedly).

Exploitation steps

  1. Craft a malicious tar archive: Create a tar file containing members with path traversal sequences. For example, add a file with the path dummy_dir/../../tmp/pwned.txt — after strip_first_component processing, this becomes ../../tmp/pwned.txt, escaping the extraction directory.
  2. Optionally embed a nested tarball: For nested tarball attacks, include a member named dummy_dir/inner.tar.gz where the inner archive itself contains traversal paths such as dummy_dir/../../config/.env, which will also be translated unsafely.
  3. Deliver the malicious archive: Host the crafted tar archive at a URL accessible to the target system, or supply it directly to any application that calls jaraco.context.tarball() or setuptools._vendor.jaraco.context.tarball() with attacker-controlled input.
  4. Trigger extraction: When the target application calls tarball(url) or processes the archive via strip_first_component, the filter strips the first path component but passes ../ sequences through, causing files to be written outside the intended extraction directory.
  5. Achieve objective: Depending on filesystem permissions, the attacker can overwrite sensitive files (e.g., configuration files, scripts), plant backdoors, or escalate privileges if the extraction process runs with elevated rights (GitHub Advisory).

Indicators of compromise

  • File System: Unexpected files appearing outside the intended extraction directory (e.g., in /tmp, parent directories, or system config paths like /etc/ or ~/.config/); files with names matching sensitive targets such as pwned.txt, .env, or modified system files with recent unexpected modification timestamps.
  • Logs: Application logs showing tar extraction operations followed by file write errors or permission denials in unexpected filesystem locations; Python tracebacks referencing strip_first_component or tarfile.extractall with unusual paths.
  • Network: Outbound HTTP/HTTPS requests from application processes to unexpected or attacker-controlled URLs serving .tar.gz or .tgz files, particularly if not matching known package repositories.
  • Process: Python processes invoking tarfile.extractall with paths containing ../ sequences visible in process arguments or system call traces (e.g., via strace or auditd).

Mitigation and workarounds

Upgrade jaraco.context to version 6.1.0 or later, which fixes the vulnerability by composing tarfile.data_filter with strip_first_component via the new _default_filter, ensuring Python's built-in tarfile security hardening is applied before path stripping (Patch Commit). If setuptools is the affected vector (via its vendored copy), update setuptools to a version that incorporates the patched jaraco.context code. As a temporary workaround where upgrading is not immediately possible, avoid processing untrusted tar archives with jaraco.context.tarball(), or manually validate all archive member paths to reject entries containing ../ before extraction. Multiple downstream IBM products (API Connect, Maximo Application Suite, Cloud Pak for Business Automation, watsonx Orchestrate, and others) have also released advisories and should be updated per their respective vendor bulletins (IBM Advisory, Oracle Advisory).

Community reactions

The vulnerability was reported by security researcher tsigouris007 and disclosed via GitHub's coordinated disclosure process on January 13, 2026. The setuptools maintainers were also notified, as the vulnerable code is vendored into setuptools. Coverage appeared on The Hacker Wire and infosec.exchange shortly after disclosure. CISA included the CVE in its weekly vulnerability bulletin (SB26-026). Ubuntu, Debian, and Linux security outlets published advisories and package updates in the weeks following disclosure (GitHub Advisory, CISA Bulletin).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

setuptools

Fixed

sid

setuptools

Affected

trixie

setuptools

Affected

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management