Skip to main content

Vendor/product archive

tar_project / tar CVEs

Beta · best-effort

5 CVEs tagged to tar_project / tar0 Critical, 4 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2026-33056

Published Mar 20, 2026

tar-rs is a tar archive reading/writing library for Rust. In versions 0.4.44 and below, when unpacking a tar archive, the tar crate's unpack_dir function uses fs::metadata() to ch…

CVSS 5.1 · Medium
evidence mentions
5
Buzz score
32.9
Vendor/product tagsBeta · best-effort

CVE-2021-38511

Published Aug 10, 2021

An issue was discovered in the tar crate before 0.4.36 for Rust. When symlinks are present in a TAR archive, extraction can create arbitrary directories via .. traversal.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-20990

Published Aug 26, 2019

An issue was discovered in the tar crate before 0.4.16 for Rust. Arbitrary file overwrite can occur via a symlink or hardlink in a TAR archive.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1