---
id: RUSTSEC-2026-0328
title: >-
  `decompress`: tar-family extractors write archive entries without a
  path-traversal check (tar-slip)
summary: >-
  `decompress`: tar-family extractors write archive entries without a
  path-traversal check (tar-slip)
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H'
vendor: decompress
product: decompress
ecosystem: rust
affected:
  - decompress >= 0.0.0-0
published: '2026-09-19'
updated: '2026-10-03'
sourceUpdated: '2026-10-03T07:30:03.083352599Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/RUSTSEC-2026-0328'
references:
  - url: 'https://crates.io/crates/decompress'
  - url: 'https://rustsec.org/advisories/RUSTSEC-2026-0328.html'
  - url: 'https://github.com/rusty-ferris-club/decompress/issues/21'
tags:
  - osv
  - rust
ingestedAt: '2026-10-04T07:27:31.044Z'
---

## Overview

The tar-family extractors in `decompress` (`.tar`, `.tar.gz`, `.tar.xz`,
`.tar.bz2`, `.tar.zst`) build each output path from the **raw archive entry path**
and write to it with no traversal check, so a malicious archive can write files
**outside** the destination directory, a "tar-slip" / zip-slip path traversal
(CWE-22 / CWE-23).

In `src/decompressors/tar_common.rs` (`tar_extract`):

```rust
let filepath = entry.path()?;                                    // raw entry path
let filepath = filepath.components().skip(opts.strip).collect::<PathBuf>();
                                     // strips leading components only — keeps `..`
let outpath = to.join(filepath);
// ...
let mut outfile = fs::File::create(&outpath)?;                   // writes anywhere
```

`.components().skip(opts.strip)` removes a fixed number of *leading* path
components but leaves interior `..` components intact so an entry named 
e.g. `../../../../home/<user>/.bashrc`, or an absolute path, resolves **outside** 
`to`. This affects all platforms.

## Affected packages

- `decompress >= 0.0.0-0`

## Remediation

Refer to the advisory for the patched release.
