Vulnerability Report: GO-2026-4869

standard library

tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU sparse map" format.

Affected Packages

Aliases

References

Credits

  • Colin Walters (walters@verbum.org), Uuganbayar Lkhamsuren (https://github.com/uug4na), Jakub Ciolek

Feedback

See anything missing or incorrect? Suggest an edit to this report.