Go standard library archive/tar

2 known vulnerabilities in Go standard library archive/tar, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-32288 CVSS 5.5 medium tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse…
  • CVE-2025-58183 CVSS 4.3 medium tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted…