Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.4%top 66%

CVE-2026-42497: CWE-59 Improper Link Resolution Before File Access ('Link Following') in BINGOS Archive::Tar

0
High
VulnerabilityCVE-2026-42497cvecve-2026-42497cwe-59cwe-732
Published: 05/26/2026 (05/26/2026, 00:17:50 UTC)
Source: CVE Database V5
Vendor/Project: BINGOS
Product: Archive::Tar

Description

Archive::Tar versions before 3.08 for Perl contain a vulnerability where hardlinks in tar archives can be extracted to attacker-controlled paths outside the intended extraction directory. This occurs because the function handling special files does not validate linknames against absolute paths or directory traversal sequences. As a result, an attacker can create a hardlink that points to a victim file's inode, allowing modification of that file through the extracted name. Additionally, file metadata such as mode, owner, and timestamps are applied to the victim file during extraction.

CVSS v3.1

Score 7.5high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected software

Affected versions
=0<3.08

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/24/2026, 17:21:22 UTC

Technical Analysis

CVE-2026-42497 is a vulnerability in BINGOS Archive::Tar affecting versions prior to 3.08. The issue arises in the _make_special_file() function, which passes the tar header's linkname directly to the link() system call without validating whether the linkname is an absolute path or contains '..' segments. This improper validation allows extraction of hardlinks to paths outside the extraction directory, effectively linking to victim files. Subsequent writes to the extracted file modify the victim file's contents, and the post-extraction chmod, chown, and utime operations apply changes to the victim file's inode. The vulnerability is classified under CWE-59 (Improper Link Resolution Before File Access) and CWE-732 (Incorrect Permission Assignment for Critical Resource).

Potential Impact

An attacker can craft a malicious tar archive that, when extracted by a vulnerable Archive::Tar version, creates hardlinks pointing to arbitrary files outside the extraction directory. This enables unauthorized modification of those victim files' contents and metadata, leading to integrity violations. The CVSS score of 7.5 (high) reflects the network attack vector, low attack complexity, no privileges required, no user interaction, and impact limited to integrity.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, avoid extracting untrusted tar archives with vulnerable versions of Archive::Tar. Consider using alternative extraction tools that properly validate linknames or manually inspect archives before extraction.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
CPANSec
Date Reserved
2026-04-27T18:34:48.417Z
Cvss Version
null
State
PUBLISHED
Remediation Level
null

Threat ID: 6a14f66ba5ae1af1aa1760a1

Added to database: 05/26/2026, 01:24:59 UTC

Last enriched: 06/24/2026, 17:21:22 UTC

Last updated: 07/31/2026, 19:22:58 UTC

Views: 150

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses