Description

tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU sparse map" format.

INFO

Published Date :

2026-04-08T01:06:57.416Z

Last Modified :

2026-04-08T01:06:57.416Z

Source :

Go
AFFECTED PRODUCTS

The following products are affected by CVE-2026-32288 vulnerability.

Vendors Products
Go Standard Library
  • Archive/tar

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact