CVE-2026-82331: Apache BuildStream: tar source extraction escape
CVE-2026-82331 lets malicious BuildStream tar sources write files on the host via symlinks.
Apache disclosed CVE-2026-82331, a moderate improper-link-resolution flaw in the tar source plugin of Apache BuildStream. Versions through 2.8.0 running on Python earlier than 3.12 allow a malicious source tarball to write files on the host with the privileges of the user running BuildStream by abusing symlinks. BuildStream 2.8.1 is unaffected. The advisory does not report active exploitation.
- Affects BuildStream through 2.8.0 when running on Python below 3.12.
- BuildStream 2.8.1 is unaffected.
- Malicious tar sources can write files as the user running BuildStream.
- Apache rates the link-following flaw moderate.
Vulnerabilities mentionedAll →
- CVE-2026-823319.8—Improper link resolution before file access ('link following') vulnerability in the `tar` source plugin of Apache BuildStream running on Python = 3.12…published
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-82331 | Improper link resolution before file access ('link following') vulnerability in the `tar` source plugin of Apache BuildStream running on Python = 3.12… Improper link resolution before file access ('link following') vulnerability in the `tar` source plugin of Apache BuildStream running on Python = 3.12, BuildStream >= 2.3.0 already makes use of the Python `tarfile` filter functionality, which blocks the symlink escape Users are recommended to upgrade to version 2.8.1, which fixes this issue. NVD description · AI analysis pending | 9.8 |
Posted by Jürg Billeter on Sep 23 Severity: moderate Affected versions: - Apache BuildStream (buildstream) through 2.8.0 - Apache BuildStream (buildstream) 2.8.1 unaffected Description: Improper link resolution before file access ('link following') vulnerability in the `tar` source plugin of Apache BuildStream running on Python < 3.12 allows malicious source tarballs to write files on the host, with the privileges of the user running BuildStream, via symlinks...
This source does not provide full text. Read it at seclists.org.