Skip to main content


🛡️ CVE-2026-42497 (HIGH): BINGOS Archive::Tar ❤.08 lets attackers create hardlinks outside extraction dirs, risking file overwrite or privilege escalation. No patch yet — avoid untrusted tar files. Details: radar.offseq.com/threat/cve-20… #OffSeq #Vulnerability #Perl #Security
in reply to

@offseq What do you mean, "no patch yet"? (Or "no official patch or remediation guidance is currently available" in your link?) Versions 3.10 and 3.08 of Archive::Tar (released one and four days ago, respectively) are available and contain a fix.

See metacpan.org/dist/Archive-Tar/….

⇧