CVE-2026-3479Disclosure

MEDIUMCVSS 0.0 · NONE

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model. pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 4d ago at 1 mentions (2026-03-18); latest day: 1
  • 5 total mentions across 5 days

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-03-18: 1Mentions · 2026-03-19: 1Mentions · 2026-03-23: 1Mentions · 2026-04-15: 1Mentions · 2026-04-28: 1Active Exploitation · 2026-03-19: 1Patch / Workaround · 2026-04-28: 1Technical Details · 2026-03-18: 1Technical Details · 2026-03-19: 1Technical Details · 2026-03-23: 1Technical Details · 2026-04-28: 103-1803-1903-2304-1504-28
Signal classification3 categories
Disclosure
240.0%
Patch
240.0%
Active Exploitation
120.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-181
Disclosure1
2026-03-191
Active Exploitation1
2026-03-231
Patch1
2026-04-151
Disclosure1
2026-04-281
Patch1
Full discourse5 posts
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Fedora updates MinGW Windows python3 to patch CVE-2026-4786, CVE-2026-6100, CVE-2026-3479, CVE-2026-1502 enabling code execution, data leaks, and HTTP header injection. https://threatcluster.io/cluster/multiple-cves-addressed-in-fedora-python3-updates-f6a2a99b

    Post summary

    Fedora released MinGW Windows python3 updates that patch multiple CVEs (CVE-2026-4786, CVE-2026-6100, CVE-2026-3479, CVE-2026-1502), mitigating potential code execution, data leaks, and HTTP header injection vulnerabilities.

    0000063
    166 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New HIGH CVE detected in AWS Lambda 🚨 CVE-2026-3479 impacts python in 6 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/476 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    The post announces a new high‑severity CVE affecting Python in several AWS Lambda base images, linking to related issue trackers but not providing concrete vulnerability or exploitation details.

    0000042
    34 followersView on X
  • WindowsForum@windowsforum
    Patch

    🧯 Python’s “trust me bro” path rules just got traversed. CVE-2026-3479 proves docs aren’t defenses—and everyone downstream pays the security tax. https://windowsforum.com/threads/cve-2026-3479-pkgutil-get_data-path-traversal-fix-in-cpython.406524/ #PathTraversal #PythonSecurity #Cve20263479 #CpythonPatch https://t.co/qJb8w4MNOK

    Post summary

    The tweet highlights a Python path‑traversal CVE (2026‑3479) and implies a patch exists, but provides no PoC, exploit, or active exploitation evidence.

    000003
    1.0K followersView on X
  • Marc-Frédéric Gomez@marcfredericgo
    Active Exploitation

    🎤 RadioCSIRT Ep.602 – Jeudi 19 mars 2026 Neuf sujets. Veille cyber quotidienne. 🔴 KEV / CISA – Ajout de CVE-2026-20131 affectant Cisco Secure Firewall et CVE-2026-20963 impactant Microsoft SharePoint. Deux vulnérabilités de type Deserialization of Untrusted Data activement exploitées. 🔴 Endpoint Management – La CISA alerte sur une attaque visant Stryker avec abus de Microsoft Intune. Exploitation de privilèges et détournement de capacités d’administration centralisée. 🔴 Ubiquiti – Vulnérabilité critique dans UniFi Network affectant plusieurs versions. Impact non documenté mais exposition directe des consoles de gestion réseau. 🔴 CERT-FR / Microsoft – Multiples vulnérabilités référencées CVE-2026-23941 à CVE-2026-4111. Impact non spécifié, dépendances Erlang, libexif et libarchive concernées. 🔴 Roundcube – Vulnérabilités multiples incluant SSRF, XSS et CSRF sur Webmail. Atteinte à la confidentialité et exécution de requêtes côté serveur possibles. 🔴 Mitel – Vulnérabilité XSS affectant MiContact Center et MCX. Injection de code côté client permettant manipulation de session et contenu. 🔴 Splunk – Vulnérabilités multiples dans Universal Forwarder. Références CVE-2025-15467, CVE-2026-22795 et CVE-2026-22796. Impact non précisé. 🔴 Python – CVE-2026-3479. Contournement de politique de sécurité dans CPython. Mécanisme d’exploitation non détaillé publiquement. 🔴 VMware Tanzu – Plus de 100 CVE dans les Buildpacks et composants plateforme. Risque Supply Chain étendu sur dépendances logicielles. 🔴 DPRK – IBM X-Force et Flare identifient une opération impliquant 100 000 faux IT workers infiltrant des entreprises occidentales. Usage de VPN, identités frauduleuses et plateformes freelance. 🔴 NCSC – Publication de recommandations sur la sécurisation des visioconférences. Risques liés aux accès, à la gestion des données et aux fonctionnalités IA. 🎧 Écoutez l'épisode complet sur toutes les plateformes de podcast. Lien direct : https://www.radiocsirt.org/podcast/ep-602-radiocsirt-edition-francaise-veille-cyber-du-jeudi-19-mars-2026/ 📌 On ne réfléchit pas, on patch ! #RadioCSIRT #Cybersécurité #ThreatIntelligence #CTI #CISA #KEV #Cisco #SharePoint #Deserialization #Endpoint #Intune #Ubiquiti #UniFi #CERTFR #Roundcube #SSRF #XSS #CSRF #Mitel #Splunk #Python #VMware #Tanzu #SupplyChain #NorthKorea #DPRK #IBM #Flare #NCSC #ZeroTrust #CVE #CERT #SOC #CISO #CyberDefense #BlueTeam #InfoSec

    Post summary

    The episode reports multiple CVEs, notably deserialization vulnerabilities in Cisco Secure Firewall and Microsoft SharePoint, that are actively being exploited, and it highlights a broader range of security issues across various vendors as identified by CISA and CERT‑FR.

    00000101
    413 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3479 pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals. https://www.cve.org/CVERecord?id=CVE-2026-3479

    Post summary

    The note announces CVE-2026-3479 as a path traversal flaw in Python’s pkgutil.get_data(), linking to the official CVE record.

    0000069
    56.8K followersView on X

Explore more