
CVE-2026-32885 DDEV is an open-source tool for running local web development environments for PHP and Node.js. Versions prior to 1.25.2 have unsanitized extraction in both `Untar()`… https://www.cve.org/CVERecord?id=CVE-2026-32885
Post summary
The CVE points to an unsanitized extraction flaw in DDEV’s Untar function affecting versions before 1.25.2, with no details of exploitation, PoC, or patch provided.

