PatchSiren cyber security CVE debrief
CVE-2026-82049 Python Software Foundation CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-14T19:17:50.927Z and has not been modified since then. The vulnerability in CPython's tarfile module allows crafted archives to modify file permissions or expose contents outside the destination directory. Defenders should verify archive integrity and update the tarfile module. The CVE details indicate a HIGH severity with a CVSS score of 8.4, emphasizing the need for prompt assessment and mitigation.
- Vendor
- Python Software Foundation
- Product
- CPython
- CVSS
- HIGH 8.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-14
- Original CVE updated
- 2026-09-30
- Advisory published
- 2026-09-14
- Advisory updated
- 2026-09-30
Who should care
Defenders responsible for CPython deployments, particularly those using the tarfile module, should assess their exposure and verify the integrity of extracted archives. This includes reviewing current CPython versions, identifying potential vulnerabilities, and implementing necessary updates or mitigations. Security teams and operators must prioritize verifying the presence of CPython 3.13 or earlier in their environments and assess the exposure of such CP
Why it matters
Defenders should prioritize verifying the presence of CPython 3.13 or earlier in their environments and assess the exposure of archives containing crafted hard links to symbolic links. The vulnerability in the tarfile module may cause extraction to modify file permissions or modification times outside the destination directory, or expose file contents within the extracted tree. Verification of archive integrity and tarfile module updates is required.
- Potential modification of file permissions or modification times outside the destination directory
- Potential exposure of file contents within the extracted tree
- Verification of archive integrity and tarfile module updates required
- Assessment of CPython 3.13 or earlier presence in the environment
Technical summary
The tarfile module in CPython 3.13 and earlier is vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree. This vulnerability can lead to unintended changes in file permissions or modification times, and potentially expose sensitive information. The affected module does not properly handle hard links to symbolic links, allowing attackers to manipulate files outside the intended extraction directory.
Defensive priority
Defenders should prioritize verifying the presence of CPython 3.13 or earlier in their environments and assess the exposure of archives containing crafted hard links to symbolic links.
Recommended defensive actions
- Verify the presence of CPython 3.13 or earlier in your environment
- Assess the exposure of archives containing crafted hard links to symbolic links
- Review and update the tarfile module to the latest version
- Implement compensating controls for exposed systems
- Monitor relevant logs for exposed assets
- Track exceptions and retest remediated assets
- Review vendor patch guidance for CPython updates
Evidence notes
The CVE record and NVD entry provide details on the vulnerability in CPython's tarfile module. However, the corpus does not establish versions, exploitation, impact, or remediation for specific systems or deployments.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-82049 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-82049
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-82049 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-82049
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/python/cpython/commit/197663d63afed27f66e10e23c194e8a634e60913
-
Source reference
Unverified legacy reference
URL: https://github.com/python/cpython/commit/28f315486b3da0352b9a1de1c3c97f4127ba4771
-
Source reference
Unverified legacy reference
URL: https://github.com/python/cpython/commit/5a57248b22ad3b9aafcaaadae2c304a1923daeca
-
Source reference
Unverified legacy reference
URL: https://github.com/python/cpython/commit/b38be2e6cf9d989075ab73412c63e003ebad4ff3
-
Source reference
Unverified legacy reference
URL: https://github.com/python/cpython/commit/b8f23e307097552eaea2604383a12ab280520d0d
-
Source reference
Unverified legacy reference
URL: https://github.com/python/cpython/issues/157190
-
Source reference
Unverified legacy reference
URL: https://github.com/python/cpython/pull/157191
-
Source reference
Unverified legacy reference
URL: https://mail.python.org/archives/list/[email protected]/thread/EFJWGAZJA56AKSBR2WHMHQZO7RRLZPRH/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.