Skip to main content

Vendor archive

archive::tar_project CVEs

Beta · best-effort

5 CVEs tagged to vendor archive::tar_project1 Critical, 3 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2026-9538

Published May 26, 2026

Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header. _read_tar() reads each entry's payload with $handle->re…

CVSS 7.5 · High
evidence mentions
4
Buzz score
32.6
Vendor/product tagsBeta · best-effort

CVE-2026-42497

Published May 26, 2026

Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory. _make_special_file() passes the tar header's linkname…

CVSS 7.5 · High
evidence mentions
4
Buzz score
36.1
Vendor/product tagsBeta · best-effort

CVE-2026-42496

Published May 26, 2026

Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkna…

CVSS 9.1 · Critical
evidence mentions
11
Buzz score
44.9
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1