CYBER CODE RED

Get real-time updates on Telegram

P5Verified

CVE-2026-82049: CPython 0 to before 3.10.22, 3.11.0 to before 3.11.17, 3.12.0 to before 3.12.15, 3.13.0 to before 3.13.16, 3.14.0a1 to…

CVE-2026-82049 affects azl3 python3 3.12.14-1 on Azure Linux 3.0. EPSS 0.00188 (percentile 0.07701), scored 2026-10-10.

Affected technology

CPython · 0 to before 3.10.22, 3.11.0 to before 3.11.17, 3.12.0 to before 3.12.15, 3.13.0 to before 3.13.16, 3.14.0a1 to before 3.14.0b1
Python Software Foundation

Description’s affected range: 3.13 and earlier, the tarfile module's data and tar extraction filters

Component: tarfile

Attack conditions (Vendor/CNA, CVSS 4.0): Local · No privileges required · Passive user interaction

What an attacker can do

Vendor/CNA’s CVSS 4.0 assessment (base score 8.4/10) rates confidentiality and integrity impact as high; availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

Published

CWE
CWE-59
Product
azl3 python3 3.12.14-1 on Azure Linux 3.0
CCR priority
0.0 /100 (P5)
EPSS
0.00188 · percentile 0.07701 · 2026-10-10
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-82049.html