CVE-2026-32288
tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU sparse map" format.
- Published Apr 8, 2026
- CVSS 5.5 medium
- 0.2% chance of exploitation in the next 30 days (EPSS)
- A fix is available