Uploaded September 2025 | Updated September 2026, 2 hours ago
(Caleb Brown) I found some vulnerabilities in Python's standard library, and now you've all had to upgrade your Python. Sorry, not sorry.
My day job is focused on open source and software supply chain security. This has made me curious - how trustworthy even are the core technologies our ecosystems are built on - like 46 year old archiving formats?
So after I read a vulnerability report that exploited symlinks in TAR files, I wondered whether Python suffered the same problem. I started poking around and ended up finding an arbitrary write path traversal in Python's standard library.
This talk will provide a detailed look at this vulnerability and demonstrate how it can be exploited by an attacker to compromise an exposed system.
I’ll also discuss how these vulnerabilities demonstrate key security challenges facing developers while building their projects. The challenges range from the different incentives between libraries and their applications, the limits of abstractions, and the difficulties of hardening legacy code.
With movement towards more regulation, like the EU's Cyber Resilience Act, and more interest in improving software security, appreciating these security challenges can help developers focus more on building exciting projects than mitigating vulnerabilities.
pretalx.com/pycon-au-2025/talk/LQD9GH
python, pycon, australia, programming, conference, technical, developers, panel, sessions, libraries, frameworks, community, sysadmins, students, education, data, science
Videos licensed as CC-BY-NC-SA 4.0
PyCon AU is the national conference for the Python programming community, bringing together professional, student and enthusiast developers, sysadmins and operations folk, students, educators, scientists, statisticians, and many others besides, all with a love for working with Python.
Licensed as CC BY-NC-SA - creativecommons.org/licenses/by-nc-sa/4.0
Produced by Next Day Video Australia: https://nextdayvideo.com.au
Sun Sep 14 13:20:00 2025 at Ballroom 2
(Caleb Brown) I found some vulnerabilities in Python's standard library, and now you've all had to upgrade your Python. Sorry, not sorry.
My day job is focused on open source and software supply chain security. This has made me curious - how trustworthy even are the core technologies our ecosystems are built on - like 46 year old archiving formats?
So after I read a vulnerability report that exploited symlinks in TAR files, I wondered whether Python suffered the same problem. I started poking around and ended up finding an arbitrary write path traversal in Python's standard library.
This talk will provide a detailed look at this vulnerability and demonstrate how it can be exploited by an attacker to compromise an exposed system.
I’ll also discuss how these vulnerabilities demonstrate key security challenges facing developers while building their projects. The challenges range from the different incentives between libraries and their applications, the limits of abstractions, and the difficulties of hardening legacy code.
With movement towards more regulation, like the EU's Cyber Resilience Act, and more interest in improving software security, appreciating these security challenges can help developers focus more on building exciting projects than mitigating vulnerabilities.
pretalx.com/pycon-au-2025/talk/LQD9GH
python, pycon, australia, programming, conference, technical, developers, panel, sessions, libraries, frameworks, community, sysadmins, students, education, data, science
Videos licensed as CC-BY-NC-SA 4.0
PyCon AU is the national conference for the Python programming community, bringing together professional, student and enthusiast developers, sysadmins and operations folk, students, educators, scientists, statisticians, and many others besides, all with a love for working with Python.
Licensed as CC BY-NC-SA - creativecommons.org/licenses/by-nc-sa/4.0
Produced by Next Day Video Australia: https://nextdayvideo.com.au
Sun Sep 14 13:20:00 2025 at Ballroom 2




