Tar is a foundational Unix archiving utility widely embedded across operating systems and build toolchains, where its vulnerability profile centers on path-handling weaknesses during archive extraction. The durable signal is a recurrence of symlink-following and path-traversal flaws—improper link resolution before file access and pathname-boundary violations—that arise from the complexity of safely extracting archives to arbitrary filesystems; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tar Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-32804HIGH The npm package "tar" (aka node-tar) before versions 6.1.1, 5.0.6, 4.4.14, and 3.3.2 has a arbitrary File Creation/Overwrite vulnerability due to insufficient absolute path sanitiz | Aug 3, 2021 | 8.1 | 33 | NO | NO |
CVE-2021-32803HIGH The npm package "tar" (aka node-tar) before versions 6.1.2, 5.0.7, 4.4.15, and 3.2.3 has an arbitrary File Creation/Overwrite vulnerability via insufficient symlink protection. `no | Aug 3, 2021 | 8.1 | 29 | NO | NO |
CVE-2026-33056MEDIUM tar-rs is a tar archive reading/writing library for Rust. In versions 0.4.44 and below, when unpacking a tar archive, the tar crate's unpack_dir function uses fs::metadata() to che | Mar 20, 2026 | 6.5 | 26 | NO | NO |
CVE-2021-38511HIGH An issue was discovered in the tar crate before 0.4.36 for Rust. When symlinks are present in a TAR archive, extraction can create arbitrary directories via .. traversal. | Aug 10, 2021 | 7.5 | 24 | NO | NO |
CVE-2018-20990HIGH An issue was discovered in the tar crate before 0.4.16 for Rust. Arbitrary file overwrite can occur via a symlink or hardlink in a TAR archive. | Aug 26, 2019 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tar Project.
Media articles that mention a CVE ID that affects a product developed by Tar Project — matched by CVE ID, not by vendor name.