CVE-2026-42496: Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory
Published May 26, 2026
·Updated
Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory
Affected Software
4 affected componentsFixes available
cpan/Archive::Tar<3.08
Microsoft azl3 perl 5.38.2-509
Archive\ \<3.08
debian/perl<=5.32.1-4+deb11u3, <=5.32.1-4+deb11u5, <=5.36.0-7+deb12u3, <=5.36.0-7+deb12u2, <=5.40.1-6, <=5.40.1-8
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Archive::Tarto a version that resolves this vulnerability.Fixed in 3.08
Event History
May 26, 2026
CVE Published
via MITRE·12:17 AM
Data Sourced
via MITRE·12:17 AM
RemedyDescriptionWeakness
Data Sourced
via Red Hat·02:01 AM
DescriptionSeverityAffected Software
Data Sourced
via NVD·02:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
May 29, 2026
Data Sourced
via Microsoft·08:08 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:08 AM
Affected Software
Updated
via Microsoft·08:08 AM
DescriptionSeverity
Jul 2, 2026
Data Sourced
via Ubuntu·09:12 AM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·09:13 AM
DescriptionAffected Software
Data Sourced
via Launchpad·09:13 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2026-42496?
The severity of CVE-2026-42496 is rated at 30.
2
How do I fix CVE-2026-42496?
To fix CVE-2026-42496, upgrade to Archive::Tar version 3.08 or later.
3
What versions of Archive::Tar are affected by CVE-2026-42496?
Archive::Tar versions prior to 3.08 are affected by CVE-2026-42496.
4
What type of vulnerability is CVE-2026-42496?
CVE-2026-42496 is a security vulnerability related to the extraction of symlinks with attacker-controlled targets.
5
Can CVE-2026-42496 lead to security risks?
Yes, CVE-2026-42496 can potentially allow attackers to control symlink targets outside the intended extraction directory.