Get real-time updates on Telegram
CVE-2026-82049: CPython 0 to before 3.10.22, 3.11.0 to before 3.11.17, 3.12.0 to before 3.12.15, 3.13.0 to before 3.13.16, 3.14.0a1 to…
CVE-2026-82049 affects azl3 python3 3.12.14-1 on Azure Linux 3.0. EPSS 0.00188 (percentile 0.07701), scored 2026-10-10.
Affected technology
CPython · 0 to before 3.10.22, 3.11.0 to before 3.11.17, 3.12.0 to before 3.12.15, 3.13.0 to before 3.13.16, 3.14.0a1 to before 3.14.0b1
Python Software Foundation
Description’s affected range: 3.13 and earlier, the tarfile module's data and tar extraction filters
Component: tarfile
Attack conditions (Vendor/CNA, CVSS 4.0): Local · No privileges required · Passive user interaction
What an attacker can do
Vendor/CNA’s CVSS 4.0 assessment (base score 8.4/10) rates confidentiality and integrity impact as high; availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.
- CWE
- CWE-59
- Product
- azl3 python3 3.12.14-1 on Azure Linux 3.0
- CCR priority
- 0.0 /100 (P5)
- EPSS
- 0.00188 · percentile 0.07701 · 2026-10-10
- KEV
- no
Provenance
- FIRST EPSS daily exploit-probability · Source record · observed 2026-10-10 21:26:32.650893+00:00 UTC
- GitHub Advisory Database · Source record · observed 2026-10-11 04:30:04.416626+00:00 UTC
- Microsoft MSRC Security Update Guide (CVRF) · Source record · observed 2026-10-04 07:08:49.022374+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-11 03:06:59.055843+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-82049.html