<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T20:43:09.934052+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-327617</id>
    <title>EUVD-2026-327617</title>
    <updated>2026-10-03T20:43:10.043897+00:00</updated>
    <content>EUVD-2026-327617</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-327617"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45390</id>
    <title>fkie_cve-2026-45390</title>
    <updated>2026-10-03T20:43:10.043933+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in its name allows escaping the current working directory. This is not desired behavior, and tar(1) rejects such extractions, but ocaml-tar decompresses it anyway. The impact is that it allows arbitrary file writes outside of the desired extraction directory (to an attacker that can reach a tar decompression endpoint).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-45390"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-x4gv-m4gg-cwm5</id>
    <title>GHSA-x4gv-m4gg-cwm5</title>
    <updated>2026-10-03T20:43:10.043967+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in its name allows escaping the current working directory. This is not desired behavior, and tar(1) rejects such extractions, but ocaml-tar decompresses it anyway. The impact is that it allows arbitrary file writes outside of the desired extraction directory (to an attacker that can reach a tar decompression endpoint).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-x4gv-m4gg-cwm5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/osec-2026-08</id>
    <title>OSEC-2026-08 — Path traversal vulnerability in ocaml-tar</title>
    <updated>2026-10-03T20:43:10.043985+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> opam: tar</p>
<p>A malicious archive with `../` path segments in its name allows escaping the current working directory. This is not desired behavior, and tar(1) rejects such extractions, but ocaml-tar decompresses it anyway.
The impact is that it allows arbitrary file write outside of the desired extraction directory to an attacker that can reach a tar decompression endpoint. In terms of severity, similar vulnerabilities in different ecosystems (python, node, go) have been assigned CVSS scores of 6.8 MEDIUM, 7.1 HIGH, and 8.2 HIGH.</p>
<p>## Details</p>
<p>Function `Tar_unix.extract` uses `Filename.concat`.</p>
<p>```OCaml
let extract ?(filter = fun _ -&gt; true) ~src dst =
  let f ?global:_ hdr () =
    if filter hdr then
      match hdr.Tar.Header.link_indicator with
      | Tar.Header.Link.Normal -&gt;
        begin match Result.map_error unix_err_to_msg
            (safe Unix.(openfile (Filename.concat dst hdr.Tar.Header.file_name)
                          [ O_WRONLY ; O_CREAT ]) hdr.Tar.Header.file_mode) with
        | Error _ as err -&gt; Tar.return err
        | Ok dst -&gt;
          try copy ~dst_fd:dst (Int64.to_int hdr.Tar.Header.file_size)
          with exn -&gt; safe_close dst; Tar.return (Error (`Exn exn))
        end
        (* TODO set owner / mode / mtime etc. *)
      | _ -&gt;
        (* TODO handle directories, links, etc. *)
        let open Tar.Syntax in
        let* () = Tar.seek (Int64.to_int hdr.Tar.Header.file_size) in
        Tar.return (Ok ())
    else
      let open Tar.Syntax in
      let* () =…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/osec-2026-08"/>
  </entry>
</feed>
