CVE-2026-82331: Apache BuildStream: tar source extraction escape
CVE-2026-82331 lets malicious BuildStream tar sources write files on the host via symlinks.
Apache disclosed CVE-2026-82331, a moderate improper-link-resolution flaw in the tar source plugin of Apache BuildStream. Versions through 2.8.0 running on Python earlier than 3.12 allow a malicious source tarball to write files on the host with the privileges of the user running BuildStream by abusing symlinks. BuildStream 2.8.1 is unaffected. The advisory does not report active exploitation.