
Perl CPAN Archive::Tar CVE-2026-42496: Extract symlinks with attacker controlled targets outside the extraction directory https://www.openwall.com/lists/oss-security/2026/05/26/2 CVE-2026-42497: ditto for hardlinks https://www.openwall.com/lists/oss-security/2026/05/26/3 CVE-2026-9538: Memory exhaustion via tar header https://www.openwall.com/lists/oss-security/2026/05/26/4
Post summary
Three new CVEs in the Perl CPAN Archive::Tar module are disclosed, detailing symlink and hardlink extraction weaknesses and a memory‑exhaustion issue via tar headers, with links to Openwall discussion posts.

