Version 0.18.3-1 of unearth is marked for autoremoval from testing on Tue 03 Nov 2026. It depends (transitively) on python-anyio, affected by #1148561. You should try to prevent the removal by fixing these RC bugs.
vcswatch reports that
this package seems to have a new changelog entry (version
0.18.3-2, distribution
unstable) and new commits
in its VCS. You should consider whether it's time to make
an upload.
1 issue left for the package maintainer to handle:
CVE-2026-73030:
(needs triaging)
unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize paths before validation, allowing ../ sequences to bypass directory containment checks. Attackers can supply malicious tar archives with symlink members or traversal sequences to write files to arbitrary filesystem locations accessible to the process.