๐Ÿ” CVE Alert

CVE-2026-42497

HIGH 7.5

Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
11th

Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory. _make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode. A subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone.

CWE CWE-59 CWE-732
Vendor bingos
Product archive::tar
Published May 26, 2026
Last Updated May 28, 2026
Stay Ahead of the Next One

Get instant alerts for bingos archive::tar

Be the first to know when new high vulnerabilities affecting bingos archive::tar are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

BINGOS / Archive::Tar
0 < 3.08

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158.patch metacpan.org: https://metacpan.org/release/BINGOS/Archive-Tar-3.08/changes cve.org: https://www.cve.org/CVERecord?id=CVE-2026-42496