Directory Traversal Affecting python3.12-wheel package, versions <0:0.41.2-4.el8_10


Severity

Recommended
high

Based on AlmaLinux security rating.

Threat Intelligence

EPSS
0.32% (25th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-ALMALINUX8-PYTHON312WHEEL-15247960
  • published7 Feb 2026
  • disclosed4 Feb 2026

Introduced: 4 Feb 2026

CVE-2026-24049  (opens in a new tab)
CWE-22  (opens in a new tab)

How to fix?

Upgrade AlmaLinux:8 python3.12-wheel to version 0:0.41.2-4.el8_10 or higher.
This issue was patched in ALSA-2026:2090.

NVD Description

Note: Versions mentioned in the description apply only to the upstream python3.12-wheel package and not the python3.12-wheel package as distributed by AlmaLinux. See How to fix? for AlmaLinux:8 relevant fixed versions and status.

wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. Attackers can craft a malicious wheel file that, when unpacked, changes the permissions of critical system files (e.g., /etc/passwd, SSH keys, config files), allowing for Privilege Escalation or arbitrary code execution by modifying now-writable scripts. This issue has been fixed in version 0.46.2.

References

CVSS Base Scores

version 3.1