CVE-2026-82049
ADVISORY - nistSummary
In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree.
Common Weakness Enumeration (CWE)
ADVISORY - nist
Improper Link Resolution Before File Access ('Link Following')
NIST
CREATED
UPDATED
ADVISORY IDCVE-2026-82049
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
8.4highDebian
CREATED
UPDATED
ADVISORY IDCVE-2026-82049
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-