8.4
CVE-2026-82049
- EPSS 0.18%
- Veröffentlicht 14.09.2026 19:17:50
- Zuletzt bearbeitet 02.10.2026 01:16:44
- Erkennungen
tarfile extraction filters allow file modification and content disclosure via hard link to symlink
In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerPython Software Foundation
≫
Produkt
CPython
Default Statusunaffected
Version
0
Version <
3.10.22
Status
affected
Version
3.11.0
Version <
3.11.17
Status
affected
Version
3.12.0
Version <
3.12.15
Status
affected
Version
3.13.0
Version <
3.13.16
Status
affected
Version
3.14.0a1
Version <
3.14.0b1
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.18% | 0.079 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| cna@python.org | 8.4 | 0 | 0 |
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-59 Improper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
https://github.com/python/cpython/commit/5a57248b22ad3b9aafcaaadae2c304a1923daeca
https://github.com/python/cpython/issues/157190
https://github.com/python/cpython/pull/157191
https://mail.python.org/archives/list/security-announce@python.org/thread/EFJWGAZJA56AKSBR2WHMHQZO7RRLZPRH/
http://www.openwall.com/lists/oss-security/2026/09/14/27
https://github.com/python/cpython/commit/b38be2e6cf9d989075ab73412c63e003ebad4ff3
https://github.com/python/cpython/commit/b8f23e307097552eaea2604383a12ab280520d0d
https://github.com/python/cpython/commit/197663d63afed27f66e10e23c194e8a634e60913
https://github.com/python/cpython/commit/28f315486b3da0352b9a1de1c3c97f4127ba4771
https://github.com/python/cpython/commit/c66df4e70435d257fd488b35ea129c6f317433a8
https://github.com/python/cpython/commit/cc1689830c6b9aaddded2fb9f2fe8116867e2c0e