Overview
What is CVE-2026-11972?
When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.
Vulnerability intelligence
CVE-2026-11972 and is rated High severity with a CVSS score of 8.2. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.