CVE-2026-82049
CVE-2026-82049 — tarfile extraction filters allow file modification and content disclosure via hard link to symlink
In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree.
Published Updated Sources: cvelistV5, PSF
Triage
Is it exploited, how likely is exploitation, what does it touch, and how severe do the scoring sources call it.
Exploitation
Unreported
no source claims exploitation
EPSS
0%
chance of exploitation in 30 days
CVSS base
8.4
HIGH
CISA SSVC assessment
Three decision points CISA publishes for the CVEs it assesses · SSVC 2.0.3. A stakeholder decision, not a severity score.
Exploitation
None
none · proof-of-concept · active
Automatable
No
can an attacker script all four kill-chain steps
Technical impact
Total
partial · total control of the vulnerable component
Affected scope
The catalog records vendors and products as separate lists, not pairs, so which product belongs to which vendor is not something this page can say.
Vendors (1)
Products (1)
Every base score collected
Sources score independently and disagree; each row says who scored it and under which version.
| Score | Version | Severity | Expl. | Impact | Source |
|---|---|---|---|---|---|
| 8.4 | CVSS 4.0 | HIGH | — | — | cvelistV5 |
Weakness & attack patterns
- CWE-59
Attack patterns reported against this CVE. The ATT&CK techniques below are inferred from its weakness class.
- T1547.009Boot or Logon Autostart Execution: Shortcut Modification
- T1574.005Hijack Execution Flow: Executable Installer File Permissions Weakness
- T1574.010Hijack Execution Flow: Services File Permissions Weakness
References
11 on the record
- github.com/python/cpython/commit/5a57248b22ad3b9aafcaaadae2c304a1923daeca
patch
- github.com/python/cpython/issues/157190
issue-tracking
- github.com/python/cpython/pull/157191
patch
- mail.python.org/archives/list/[email protected]/thread/EFJWGAZJA56AKSBR2WHMHQZO7RRLZPRH/
vendor-advisory
- github.com/python/cpython/commit/b38be2e6cf9d989075ab73412c63e003ebad4ff3
patch
- github.com/python/cpython/commit/b8f23e307097552eaea2604383a12ab280520d0d
patch
- github.com/python/cpython/commit/197663d63afed27f66e10e23c194e8a634e60913
patch
- github.com/python/cpython/commit/28f315486b3da0352b9a1de1c3c97f4127ba4771
patch
Elsewhere on this site
- python software foundationevery CVE for this vendor
- CWE-59other pages naming this weakness
Not in any source we poll
Listed rather than left blank: an empty field and an unmeasured one look identical on screen, and only one is a reason to look elsewhere.
- No confirmed IOCs, IP addresses, domains, file hashes, or malware artifacts supplied.
- No organization-specific asset inventory, compensating-control status, or patch deployment evidence supplied.
- No exploit packet captures, log samples, or incident case IDs supplied.