
Perl CPAN Archive::Tar CVE-2026-42496: Extract symlinks with attacker controlled targets outside the extraction directory https://www.openwall.com/lists/oss-security/2026/05/26/2 CVE-2026-42497: ditto for hardlinks https://www.openwall.com/lists/oss-security/2026/05/26/3 CVE-2026-9538: Memory exhaustion via tar header https://www.openwall.com/lists/oss-security/2026/05/26/4
Post summary
The text announces three new CVEs (CVE-2026-42496, CVE-2026-42497, CVE-2026-9538) affecting Perl CPAN Archive::Tar, outlining symlink, hardlink, and memory exhaustion issues, with links to supporting discussion posts but no PoC, exploit, or patch information.


