
Perl CPAN Archive::Tar CVE-2026-42496: Extract symlinks with attacker controlled targets outside the extraction directory https://www.openwall.com/lists/oss-security/2026/05/26/2 CVE-2026-42497: ditto for hardlinks https://www.openwall.com/lists/oss-security/2026/05/26/3 CVE-2026-9538: Memory exhaustion via tar header https://www.openwall.com/lists/oss-security/2026/05/26/4
Post summary
Three CVEs in Perl CPAN Archive::Tar were disclosed, describing symlink/hardlink extraction outside the target directory and memory exhaustion via tar header; advisory links are provided but no PoC, exploit, or patches are mentioned.

