Archive/tar
This hub aggregates every CVE we track for Archive/tar, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
6
CVEs tracked
1
Critical
3
High
0
In CISA KEV
Severity distribution
HIGH3MEDIUM2CRITICAL1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
0
1
3
0
0
0
2024-092026-08
Latest CVEs
The 6 most recently published vulnerabilities affecting Archive/tar.
- CVE-2026-9538Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header7.5
- CVE-2026-42497Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory7.5
- CVE-2026-42496Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory9.1
- CVE-2026-32288Unbounded allocation for old GNU sparse in archive/tar5.5
- CVE-2025-58183Unbounded allocation when parsing GNU sparse map in archive/tar4.3
- CVE-2022-2879Unbounded memory consumption when reading headers in archive/tar7.5
Product normalization is registry-driven with AI assist and human review. How it works