Improper Link Resolution Vulnerability in Apache BuildStream Source Plugin
CVE-2026-82331

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
23 September 2026

What is CVE-2026-82331?

A vulnerability exists in the 'tar' source plugin of Apache BuildStream, enabling malicious source tarballs to exploit improper link resolution, potentially writing files on the host system. This occurs when symlinks are used in source fetching, leading the user executing BuildStream to inadvertently allow unauthorized file access. While the issue can be mitigated by only using trusted sources, the recommended action is to upgrade to BuildStream version 2.8.1 to eliminate this vulnerability entirely. Ensure you are using Python version 3.12 or higher for added protection, as newer versions leverage the Python tarfile filter functionality to prevent symlink escapes.

Affected Version(s)

Apache BuildStream 0 <= 2.8.0

Apache BuildStream 2.8.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gjoko Krstic of Zero Science Lab
.