-------- Forwarded Message --------
Subject: [Security-announce][CVE-2026-82049] tarfile extraction filters allow file modification and content disclosure via hard link to symlink
Date:   Mon, 14 Sep 2026 17:59:38 +0100
From:   Stan Ulbrych via Security-announce <[email protected]>
Reply-To:       [email protected]
To:     [email protected]
CC:     Stan Ulbrych <[email protected]>

There is a HIGH severity vulnerability affecting CPython.

In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree.

Please see the linked CVE ID for the latest information on affected versions:

* https://www.cve.org/CVERecord?id=CVE-2026-82049
* https://github.com/python/cpython/pull/157192

--
Stan Ulbrych  (https://stan.ulbrych.org <https://stan.ulbrych.org>)
_______________________________________________
Security-announce mailing list -- [email protected]
https://mail.python.org/mailman3//lists/security-announce.python.org

Reply via email to