๐Ÿ” CVE Alert

CVE-2026-9538

HIGH 7.5

Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
12th

Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header. _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value. A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size.

CWE CWE-789
Vendor bingos
Product archive::tar
Published May 26, 2026
Last Updated May 28, 2026
Stay Ahead of the Next One

Get instant alerts for bingos archive::tar

Be the first to know when new high vulnerabilities affecting bingos archive::tar are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

BINGOS / Archive::Tar
0 < 3.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/jib/archive-tar-new/commit/f9af01426038e29d9578825a0cd3626946ab08c7.patch metacpan.org: https://metacpan.org/release/BINGOS/Archive-Tar-3.10/changes openwall.com: http://www.openwall.com/lists/oss-security/2026/05/26/4