CVE-2026-82331
CVE-2026-82331: 2 tracked advisory records across Apache, Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Apache
1 advisory- Advisory severityCritical9.8
Critical [CVE-2026-82331] Improper link resolution before file access ('link following') vulnerability in the `tar` source plugin of Apache BuildStream running on Python < 3.12 allows malicious source tarballs to write files on the host, with the privileges of the user running BuildStream, via symlinks as part of source fetching
CVE-2026-82331Source published Source updated
Improper link resolution before file access ('link following') vulnerability in the `tar` source plugin of Apache BuildStream running on Python = 3.12, BuildStream >= 2.3.0 already makes use of the Python `tarfile` filter functionality, which blocks the symlink escape Users are recommended to upgrade to version 2.8.1, which fixes this issue.
- Affected products in this advisory
- Apache BuildStream
- Source-reported affected versions
- Apache BuildStream through 2.8.0
- Source-reported fixed versions
- 2.8.1
- Mitigation guidance
- The impact of this issue is mitigated by: * BuildStream projects should only use trusted sources in their elements as otherwise the build output can also not be trusted * Tracking a source tarball pins its SHA256 hash, which prevents MITM attacks of users that are fetching an already tracked project * When running on Python >= 3.12, BuildStream >= 2.3.0 already makes use of the Python `tarfile` filter functionality, which blocks the symlink escape Users are recommended to upgrade to version 2.8.1, which fixes this issue.
Red Hat
1 advisory- Advisory severityMedium6.6
Medium [CVE-2026-82331] Arbitrary file write via symlinks in tar source plugin
CVE-2026-82331Source published Source updated
Arbitrary file write via symlinks in tar source plugin. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-59.
- Related products — impact not confirmed
- No product details extracted. Check the source bulletin.
- Source-reported affected versions
- < 3.12
- Source-reported fixed versions
- 3.12
- 2.3.0
- 2.8.1
- Mitigation guidance
- No mitigation guidance extracted; consult the source.
Android app · Google Play
Turn CVE research into alerts on your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.