CVE-2026-32288
Unbounded allocation for old GNU sparse in archive/tar
CVSS Score
5.5
EPSS Score
0.0%
EPSS Percentile
1th
tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU sparse map" format.
| Vendor | go standard library |
| Product | archive/tar |
| Published | Apr 8, 2026 |
| Last Updated | Apr 13, 2026 |
Stay Ahead of the Next One
Get instant alerts for go standard library archive/tar
Be the first to know when new medium vulnerabilities affecting go standard library archive/tar are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Go standard library / archive/tar
0 < 1.25.9 1.26.0-0 < 1.26.2