VulnSea

tar vulnerabilities

CVEs whose affected-version data names the tar package (npm, rust). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

11 CVEsRSS

CVE-2026-18508Medium· 4.4
1mo ago

A flaw was found in GNU tar

A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted arch…

Sunlitgnu · tarEPSS 0.14%via NVD
CVE-2026-18477Medium· 4.4
1mo ago

A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access …

A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access …

Sunlitgnu · tarEPSS 0.08%via NVD
GHSA-r292-9mhp-454mMedium· 5.3
2mo ago

node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection

node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection

Sunlittar · tarvia GHSA
CVE-2026-59875Medium· 5.3
2mo ago

node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records

node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records

Sunlittar · tarEPSS 0.51%via GHSA
CVE-2026-53655Medium
3mo ago

node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)

node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)

Sunlittar · tarEPSS 0.16%via GHSA
CVE-2026-5704Medium· 5.0
5mo ago

A flaw was found in tar

A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, pot…

Sunlitgnu · tarEPSS 0.40%via NVD
CVE-2026-29786Medium· 6.3PoC
6mo ago

node-tar is a full-featured Tar for Node.js

node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction directory by using a drive-relative link target such as C:../target.txt, which enables f…

Twilightisaacs · tarEPSS 0.44%via NVD
CVE-2026-24842High· 8.2
7mo ago

node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic

node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attac…

Twilightisaacs · tarEPSS 0.56%via NVD
CVE-2026-23950High· 8.8
8mo ago

node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3

node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path-reservations` system. On case-insensitive or normalizatio…

Twilightisaacs · tarEPSS 0.26%via NVD
CVE-2026-23745Medium· 6.1PoC
8mo ago

node-tar is a Tar for Node.js

node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries when preservePaths is false (the default secure behavior). This allows malicious archives to bypass…

Twilightisaacs · tarEPSS 0.38%via NVD
CVE-2021-38511High· 7.5
5y ago

Links in archive can create arbitrary directories

Links in archive can create arbitrary directories

Twilighttar · tarEPSS 1.4%via OSV
tar vulnerabilities (CVEs) · VulnSea