<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 13:42:51 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-327617</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-327617</link>
      <description>EUVD-2026-327617</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-327617</guid>
    </item>
    <item>
      <title>fkie_cve-2026-45390</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45390</link>
      <description>&lt;p&gt;In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in its name allows escaping the current working directory. This is not desired behavior, and tar(1) rejects such extractions, but ocaml-tar decompresses it anyway. The impact is that it allows arbitrary file writes outside of the desired extraction directory (to an attacker that can reach a tar decompression endpoint).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in its name allows escaping the current working directory. This is not desired behavior, and tar(1) rejects such extractions, but ocaml-tar decompresses it anyway. The impact is that it allows arbitrary file writes outside of the desired extraction directory (to an attacker that can reach a tar decompression endpoint).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-45390</guid>
    </item>
    <item>
      <title>GHSA-x4gv-m4gg-cwm5</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x4gv-m4gg-cwm5</link>
      <description>&lt;p&gt;In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in its name allows escaping the current working directory. This is not desired behavior, and tar(1) rejects such extractions, but ocaml-tar decompresses it anyway. The impact is that it allows arbitrary file writes outside of the desired extraction directory (to an attacker that can reach a tar decompression endpoint).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in its name allows escaping the current working directory. This is not desired behavior, and tar(1) rejects such extractions, but ocaml-tar decompresses it anyway. The impact is that it allows arbitrary file writes outside of the desired extraction directory (to an attacker that can reach a tar decompression endpoint).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x4gv-m4gg-cwm5</guid>
    </item>
    <item>
      <title>OSEC-2026-08 — Path traversal vulnerability in ocaml-tar</title>
      <link>https://cve.radiocsirt.org/vuln/osec-2026-08</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; opam: tar&lt;/p&gt;
&lt;p&gt;A malicious archive with `../` path segments in its name allows escaping the current working directory. This is not desired behavior, and tar(1) rejects such extractions, but ocaml-tar decompresses it anyway.
The impact is that it allows arbitrary file write outside of the desired extraction directory to an attacker that can reach a tar decompression endpoint. In terms of severity, similar vulnerabilities in different ecosystems (python, node, go) have been assigned CVSS scores of 6.8 MEDIUM, 7.1 HIGH, and 8.2 HIGH.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;Function `Tar_unix.extract` uses `Filename.concat`.&lt;/p&gt;
&lt;p&gt;```OCaml
let extract ?(filter = fun _ -&amp;gt; true) ~src dst =
  let f ?global:_ hdr () =
    if filter hdr then
      match hdr.Tar.Header.link_indicator with
      | Tar.Header.Link.Normal -&amp;gt;
        begin match Result.map_error unix_err_to_msg
            (safe Unix.(openfile (Filename.concat dst hdr.Tar.Header.file_name)
                          [ O_WRONLY ; O_CREAT ]) hdr.Tar.Header.file_mode) with
        | Error _ as err -&amp;gt; Tar.return err
        | Ok dst -&amp;gt;
          try copy ~dst_fd:dst (Int64.to_int hdr.Tar.Header.file_size)
          with exn -&amp;gt; safe_close dst; Tar.return (Error (`Exn exn))
        end
        (* TODO set owner / mode / mtime etc. *)
      | _ -&amp;gt;
        (* TODO handle directories, links, etc. *)
        let open Tar.Syntax in
        let* () = Tar.seek (Int64.to_int hdr.Tar.Header.file_size) in
        Tar.return (Ok ())
    else
      let open Tar.Syntax in
      let* () =…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; opam: tar&lt;/p&gt;
&lt;p&gt;A malicious archive with `../` path segments in its name allows escaping the current working directory. This is not desired behavior, and tar(1) rejects such extractions, but ocaml-tar decompresses it anyway.
The impact is that it allows arbitrary file write outside of the desired extraction directory to an attacker that can reach a tar decompression endpoint. In terms of severity, similar vulnerabilities in different ecosystems (python, node, go) have been assigned CVSS scores of 6.8 MEDIUM, 7.1 HIGH, and 8.2 HIGH.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;Function `Tar_unix.extract` uses `Filename.concat`.&lt;/p&gt;
&lt;p&gt;```OCaml
let extract ?(filter = fun _ -&amp;gt; true) ~src dst =
  let f ?global:_ hdr () =
    if filter hdr then
      match hdr.Tar.Header.link_indicator with
      | Tar.Header.Link.Normal -&amp;gt;
        begin match Result.map_error unix_err_to_msg
            (safe Unix.(openfile (Filename.concat dst hdr.Tar.Header.file_name)
                          [ O_WRONLY ; O_CREAT ]) hdr.Tar.Header.file_mode) with
        | Error _ as err -&amp;gt; Tar.return err
        | Ok dst -&amp;gt;
          try copy ~dst_fd:dst (Int64.to_int hdr.Tar.Header.file_size)
          with exn -&amp;gt; safe_close dst; Tar.return (Error (`Exn exn))
        end
        (* TODO set owner / mode / mtime etc. *)
      | _ -&amp;gt;
        (* TODO handle directories, links, etc. *)
        let open Tar.Syntax in
        let* () = Tar.seek (Int64.to_int hdr.Tar.Header.file_size) in
        Tar.return (Ok ())
    else
      let open Tar.Syntax in
      let* () =…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/osec-2026-08</guid>
    </item>
  </channel>
</rss>
