Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CVE-2026-33056
tar-rs is a tar archive reading/writing library for Rust. In versions 0.4.44 and below, when unpacking a tar archive, the tar crate's unpack_dir func…
Fix: 0.4.45+
Fix from $1,600
2026-03-20
CVE-2021-38511
An issue was discovered in the tar crate before 0.4.36 for Rust. When symlinks are present in a TAR archive, extraction can create arbitrary director…
Fix: 0.4.36+
Fix from $1,950
2021-08-10
Tar
HIGH 8.1
CVE-2021-32803EPSS 8%
The npm package "tar" (aka node-tar) before versions 6.1.2, 5.0.7, 4.4.15, and 3.2.3 has an arbitrary File Creation/Overwrite vulnerability via insuf…
Fix: 1.0.1.1 / 3.2.3+
Fix from $1,950
2021-08-03
Tar
HIGH 8.1
CVE-2021-32804EPSS 15%
The npm package "tar" (aka node-tar) before versions 6.1.1, 5.0.6, 4.4.14, and 3.3.2 has a arbitrary File Creation/Overwrite vulnerability due to ins…
Fix: 1.0.1.1 / 3.2.2+
Fix from $1,950
2021-08-03
Tar
HIGH 7.5
CVE-2018-20990
An issue was discovered in the tar crate before 0.4.16 for Rust. Arbitrary file overwrite can occur via a symlink or hardlink in a TAR archive.
Fix: 0.4.16+
Fix from $1,950
2019-08-26