CVE-2026-42496Disclosure(archive\ / \)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch archive\ \ systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted name reads or writes the attacker chosen path.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-59CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • \

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-05-26); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
\

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-05-26: 3Mentions · 2026-05-30: 1Patch / Workaround · 2026-05-30: 1Technical Details · 2026-05-26: 1Technical Details · 2026-05-30: 105-2605-30
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-05-263
Disclosure1General2
2026-05-301
Disclosure1
Full discourse4 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN Archive::Tar CVE-2026-42496: Extract symlinks with attacker controlled targets outside the extraction directory https://www.openwall.com/lists/oss-security/2026/05/26/2 CVE-2026-42497: ditto for hardlinks https://www.openwall.com/lists/oss-security/2026/05/26/3 CVE-2026-9538: Memory exhaustion via tar header https://www.openwall.com/lists/oss-security/2026/05/26/4

    Post summary

    The text announces three new CVEs (CVE-2026-42496, CVE-2026-42497, CVE-2026-9538) affecting Perl CPAN Archive::Tar, outlining symlink, hardlink, and memory exhaustion issues, with links to supporting discussion posts but no PoC, exploit, or patch information.

    01051643
    4.7K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Critical - Perl Archive::Tar Symlink Path Traversal (CVE-2026-42496) _make_special_file() passes a tar header's linkname directly to symlink() without validating for absolute paths or .. segments, and the secure-extract mode check that protects regular files does not cover symlink targets. An attacker-crafted archive can plant symlinks pointing to arbitrary locations outside the extraction directory, enabling reads or writes to attacker-chosen paths on the filesystem (CVSS 9.1). 👉 Affected: Archive::Tar (Perl) < 3.08 | Upgrade to 3.08

    Post summary

    The post discloses a critical Symlink Path Traversal flaw in Perl’s Archive::Tar (CVE‑2026‑42496), detailing the technical root cause and CVSS score, and recommends upgrading to version 3.08 to mitigate the issue.

    0000083
    196 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-42496 CVE-2026-42496 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42496

    Post summary

    The text merely lists CVE-2026-42496 and a link to vulmon, offering no further information or context about the vulnerability.

    0000085
    4.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-42497 CVE-2026-42496 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42497 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The post lists two CVE identifiers and links to a vulnerability details page, but provides no additional technical information, PoC, exploitation status, patches, or corrective claims.

    0000078
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apparchive\\tar_project--

Explore more