Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-32288

Опубликовано: 08 апр. 2026
Источник: nvd
CVSS3: 5.5
EPSS Низкий

Описание

tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU sparse map" format.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*
Версия до 1.25.9 (исключая)
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*
Версия от 1.26.0 (включая) до 1.26.2 (исключая)

EPSS

Процентиль: 21%
0.0029
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 5.5
ubuntu
4 месяца назад

tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU sparse map" format.

CVSS3: 4.3
redhat
4 месяца назад

tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU sparse map" format.

CVSS3: 5.5
msrc
4 месяца назад

Unbounded allocation for old GNU sparse in archive/tar

CVSS3: 5.5
debian
4 месяца назад

tar.Reader can allocate an unbounded amount of memory when reading a m ...

CVSS3: 5.5
github
4 месяца назад

tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU sparse map" format.

EPSS

Процентиль: 21%
0.0029
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-770