The Archive Project maintains a focused archival and data-preservation product whose vulnerability exposure centers on input-handling weaknesses, particularly improper input validation and path-traversal flaws that can arise in systems processing untrusted file metadata and archive formats. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Archive Project over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-42496CRITICAL Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.
_make_special_file() passes the tar header's linknam | May 26, 2026 | 9.1 | 39 | NO | NO |
CVE-2026-9538HIGH Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.
_read_tar() reads each entry's payload with $handle->rea | May 26, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-42497HIGH Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.
_make_special_file() passes the tar header's linkname t | May 26, 2026 | 7.5 | 30 | NO | NO |
CVE-2018-12015HIGH In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file con | Jun 7, 2018 | 7.5 | 28 | NO | NO |
CVE-2023-39139HIGH An issue in Archive v3.3.7 allows attackers to execute a path traversal via extracting a crafted zip file. | Aug 30, 2023 | 7.8 | 22 | NO | NO |
CVE-2023-39137HIGH An issue in Archive v3.3.7 allows attackers to spoof zip filenames which can lead to inconsistent filename parsing. | Aug 30, 2023 | 7.8 | 20 | NO | NO |
CVE-2007-4829MEDIUM Directory traversal vulnerability in the Archive::Tar Perl module 1.36 and earlier allows user-assisted remote attackers to overwrite arbitrary files via a TAR archive that contain | Nov 2, 2007 | 6.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Archive Project.
Media articles that mention a CVE ID that affects a product developed by Archive Project — matched by CVE ID, not by vendor name.