CVE-2026-82049: Python Software Foundation Cpython

High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.

In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree.

Affected products

  • Python Software Foundation Cpython: before 3.10.22 (fixed in 3.10.22); from 3.11.0, before 3.11.17 (fixed in 3.11.17); from 3.12.0, before 3.12.15 (fixed in 3.12.15); from 3.13.0, before 3.13.16 (fixed in 3.13.16); from 3.14.0a1, before 3.14.0b1 (fixed in 3.14.0b1)

Published 2026-09-14. Last modified 2026-10-11.