CVE-2026-82049

Summary

In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree.

Affected Software

VendorProductVersion RangeStatus
Python Software FoundationCPython0 < 3.14.0b1affected

Weaknesses

  • CWE-59: CWE-59

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

CVE Program Container

Additional References

References