Description
When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None.
Published: 2026-09-11
Score: 5.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local directory traversal via improper hardlink extraction
Action: Apply patch
AI Analysis

Impact

The tarfile module in CPython mis‑handles hardlink extraction when the underlying system does not support hardlinks. It falls back to extracting the target file, running the user‑supplied filter twice— for the linked file path. In one of these invocations, the returned value is ignored, allowing an archive that contains a hardlink to override the filter decision and extract to an arbitrary location on the host filesystem. This flaw can result in a directory traversal that permits local file write or overwrite, effectively enabling a partial privilege escalation within the context of the running Python process.

Affected Systems

Python Software Foundation: CPython. All releases prior to the commits that introduced the fix (d9565e54b1fc6d63c5be9afd58114499128fa57b and fb2f0bbc3b35264f09cc2cb2934b7987527a6bc2) are potentially vulnerable. No specific version numbers are provided, so any CPython version older than the patched commit is at risk.

Risk and Exploitability

The CVSS score of 5.7 indicates moderate severity. The EPSS score is reported to be below 1%, implying a low historical exploitation probability, although the vulnerability can still be abused by an attacker who supplies a malicious tar archive to a Python program that processes tarfiles without the patch. The flaw is not listed in the CISA KEV catalog, so no confirmed active exploitation is documented. The attack vector is local: the adversary must provide a crafted tar archive to an application that uses tarfile.extract on a system lacking hardlink support.

Generated by OpenCVE AI on September 21, 2026 at 04:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade CPython to a version that includes the patches from commits d9565e54b1fc6d63c5be9afd58114499128fa57b and fb2f0bbc3b35264f09cc2cb2934b7987527a6bc2.
  • Modify your extraction filter to explicitly reject hardlink entries; for example, in the filter function return None for any member where member.islnk() is true or where member.lnkname is set.
  • If upgrading or custom filtering is not possible, disable hardlink support in your extraction logic by ignoring any tar archive members flagged as hardlink entries or by running the extraction as a non‑privileged user.

Generated by OpenCVE AI on September 21, 2026 at 04:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 01:00:00 +0000


Thu, 01 Oct 2026 01:15:00 +0000


Wed, 30 Sep 2026 21:00:00 +0000


Tue, 22 Sep 2026 01:00:00 +0000


Mon, 14 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-252
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N'}

threat_severity

Moderate


Sat, 12 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Python
Python cpython
Vendors & Products Python
Python cpython

Sat, 12 Sep 2026 01:00:00 +0000


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None.
Title tarfile hardlink fallback ignores custom extraction filter rejection via None
Weaknesses CWE-22
CWE-59
References
Metrics cvssV4_0

{'score': 5.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: PSF

Published:

Updated: 2026-10-02T00:35:07.049Z

Reserved: 2026-09-09T15:11:08.270Z

Link: CVE-2026-87910

cve-icon Vulnrichment

Updated: 2026-09-11T21:07:14.642Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-11T18:16:59.800

Modified: 2026-10-02T01:16:44.773

Link: CVE-2026-87910

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T17:27:04Z

Links: CVE-2026-87910 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T04:30:08Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-252

    Unchecked Return Value

  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')