Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Archive Project

First CVE: Aug 30, 2023Active for: 3 yearsTotal CVEs: 7

The Archive Project maintains a focused archival and data-preservation product whose vulnerability exposure centers on input-handling weaknesses, particularly improper input validation and path-traversal flaws that can arise in systems processing untrusted file metadata and archive formats. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 56% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 74% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Archive Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 2, 2007
18 years ago
Most Recent CVE
May 26, 2026
59 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-42496CRITICAL
Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linknam
May 26, 20269.139NONO
CVE-2026-9538HIGH
Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header. _read_tar() reads each entry's payload with $handle->rea
May 26, 20267.532NONO
CVE-2026-42497HIGH
Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory. _make_special_file() passes the tar header's linkname t
May 26, 20267.530NONO
CVE-2018-12015HIGH
In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file con
Jun 7, 20187.528NONO
CVE-2023-39139HIGH
An issue in Archive v3.3.7 allows attackers to execute a path traversal via extracting a crafted zip file.
Aug 30, 20237.822NONO
CVE-2023-39137HIGH
An issue in Archive v3.3.7 allows attackers to spoof zip filenames which can lead to inconsistent filename parsing.
Aug 30, 20237.820NONO
CVE-2007-4829MEDIUM
Directory traversal vulnerability in the Archive::Tar Perl module 1.36 and earlier allows user-assisted remote attackers to overwrite arbitrary files via a TAR archive that contain
Nov 2, 20076.820NONO
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
14%
71%
14%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (28.6%)
Network4 (57.1%)
Unknown1 (14.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (85.7%)
High0 (0.0%)
Unknown1 (14.3%)
User Interaction
None4 (57.1%)
Unknown1 (14.3%)
Required2 (28.6%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None6 (85.7%)
Unknown1 (14.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Archive Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Archive Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Archive Project's Products

View all 3 CNAs →

Top CWEs