High severityNVD Advisory· Published Sep 14, 2026· Updated Sep 14, 2026
CVE-2026-82049
CVE-2026-82049
Description
In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: <=3.13
Patches
Vulnerability mechanics
References
5- www.openwall.com/lists/oss-security/2026/09/14/27nvd
- github.com/python/cpython/commit/5a57248b22ad3b9aafcaaadae2c304a1923daecanvd
- github.com/python/cpython/issues/157190nvd
- github.com/python/cpython/pull/157191nvd
- mail.python.org/archives/list/[email protected]/thread/EFJWGAZJA56AKSBR2WHMHQZO7RRLZPRH/nvd
News mentions
0No linked articles in our index yet.