Tar
Tar Project · 5 CVEs
CVE-2026-33056
MEDIUM
tar-rs: unpack_in can chmod arbitrary directories by following symlinks
Mar 20, 2026
CVE-2021-38511
HIGH
tar-crate: links in archive can create arbitrary directories
Aug 10, 2021
CVE-2021-32804
HIGH
Arbitrary File Creation/Overwrite due to insufficient absolute path sanitization
Aug 3, 2021
CVE-2021-32803
HIGH
Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning
Aug 3, 2021
CVE-2018-20990
HIGH
An issue was discovered in the tar crate before 0.4.16 for Rust. Arbitrary file overwrite can occur via a symlink or ha…
Aug 26, 2019
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-33056 | tar-rs: unpack_in can chmod arbitrary directories by following symlinks | MEDIUM | 0.41% | Mar 20, 2026 |
| CVE-2021-38511 | tar-crate: links in archive can create arbitrary directories | HIGH | 1.39% | Aug 10, 2021 |
| CVE-2021-32804 | Arbitrary File Creation/Overwrite due to insufficient absolute path sanitization | HIGH | 15.13% | Aug 3, 2021 |
| CVE-2021-32803 | Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning | HIGH | 7.80% | Aug 3, 2021 |
| CVE-2018-20990 | An issue was discovered in the tar crate before 0.4.16 for Rust. Arbitrary file overwrite can occur via a symlink or hardlink in a TAR archive. | HIGH | 1.68% | Aug 26, 2019 |
Showing 1 to 5 of 5 CVEs