VendorsTar Projecttarany version
Vulnerabilities

Tar Project Tar any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2021-32804
Arbitrary File Creation/Overwrite due to insufficient absolute path sanitization
Published 2021-08-03 · Modified
8.2EPSS 0.151
CVE-2021-32803
Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning
Published 2021-08-03 · Modified
8.2EPSS 0.078
CVE-2018-20990
An issue was discovered in the tar crate before 0.4.16 for Rust. Arbitrary file overwrite can occur via a symlink or hardlink in a TAR archive.
Published 2019-08-26 · Modified
7.5EPSS 0.017
CVE-2021-38511
An issue was discovered in the tar crate before 0.4.36 for Rust. When symlinks are present in a TAR archive, extraction can create arbitrary directories via .. traversal.
Published 2021-08-10 · Modified
7.5EPSS 0.014
CVE-2026-33056
tar-rs: unpack_in can chmod arbitrary directories by following symlinks
Published 2026-03-20 · Analyzed
6.5EPSS 0.004