Known vulnerabilities in tar-rs
Vendor:
Alex Crichton
Software:
tar-rs
Software CPE:
cpe:2.3:a:alexcrichton:tar-rs:*:*:*:*:*:*:*:*
Website:
https://github.com/alexcrichton
Total vulnerabilities:
5
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.7
Breakdown by Severity Chart
0.4.46
0.4.45
0.4.44
0.4.43
0.4.42
0.4.41
0.4.40
0.4.39
0.4.38
0.4.37
0.4.36
0.4.35
0.4.34
0.4.33
0.4.32
0.4.31
0.4.30
0.4.29
0.4.28
0.4.27
0.4.26
0.4.25
0.4.24
0.4.23
0.4.22
0.4.21
0.4.20
0.4.19
0.4.18
0.4.17
0.4.16
0.4.15
0.4.14
0.4.13
0.4.12
0.4.11
0.4.10
0.4.9
0.4.8
0.4.7
0.4.6
0.4.5
0.4.4
0.4.3
0.4.2
0.4.1
0.4.0
0.3.4
0.3.3
0.3.2
0.3.1
0.3.0
0.2.14
0.2.13
0.2.12
0.2.11
0.2.10
0.2.9
0.2.8
0.2.7
0.2.6
0.2.5
0.2.4
0.2.2
0.2.1
0.1.11
0.1.10
0.1.9
0.1.8
0.1.7
0.1.6
0.1.0
Vulnerabilities (5)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU131747 - Improper input validation |
CWE-20 | Medium | 0.4.46 | 18.05.2026 |
SB2026051893 |
||
| #VU131730 - Improper Access Control |
CWE-284 | Low | 0.4.45 | 18.05.2026 |
SB2026042866 |
||
| #VU128323 - UNIX Symbolic Link (Symlink) Following CVE-2026-33056 |
CWE-61 | Medium | 0.4.45 | 28.04.2026 |
SB2026042866 SB2026042889 SB2026042890 and 61 more |
||
| #VU128322 - Improper input validation CVE-2026-33055 |
CWE-20 | Low | 0.4.45 | 28.04.2026 |
SB2026042866 |
||
| #VU78930 - Incorrect Default Permissions CVE-2023-38497 |
CWE-276 | Low | 0.4.39 | 03.08.2023 |
SB2023080354 SB2023080355 SB2023080365 and 16 more |