rootpwn

critical · CVSS v3 9.8 · EPSS 0.00195

CVE-2026-82331

Improper link resolution before file access ('link following') vulnerability in the `tar` source plugin of Apache BuildS…

Description

Improper link resolution before file access ('link following') vulnerability in the `tar` source plugin of Apache BuildStream running on Python = 3.12, BuildStream >= 2.3.0 already makes use of the Python `tarfile` filter functionality, which blocks the symlink escape Users are recommended to upgrade to version 2.8.1, which fixes this issue.

Scores

Severity
critical
CVSS v2
10
CVSS v3
9.8
CVSS v4
EPSS
0.00195

← All CVEs