Skip to content

Reject ZIP/tar polyglot files#19638

Merged
miketheman merged 4 commits into
pypi:mainfrom
sethmlarson:zip-tar
Mar 9, 2026
Merged

Reject ZIP/tar polyglot files#19638
miketheman merged 4 commits into
pypi:mainfrom
sethmlarson:zip-tar

Conversation

@sethmlarson

@sethmlarson sethmlarson commented Mar 6, 2026

Copy link
Copy Markdown
Contributor

Files can be both a ZIP and a tar, due to ZIP metadata being at the end of the file.

@sethmlarson sethmlarson marked this pull request as ready for review March 6, 2026 21:37
@sethmlarson sethmlarson requested a review from a team as a code owner March 6, 2026 21:37

@miketheman miketheman left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks!

@miketheman miketheman merged commit b6bfe62 into pypi:main Mar 9, 2026
21 checks passed
@miketheman

Copy link
Copy Markdown
Member

Note: solves for CVE-2026-3219.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants