tar is vulnerable to Interpretation Conflict
57
Medium Risk
tar applies PAX extended header size= overrides to any following header, including GNU long-name and long-link metadata entries. An attacker can craft a tar archive that causes tar to read a different sequence of members than GNU tar, libarchive, Python tarfile, or Rust tar-rs. The parser differential lets a malicious file be hidden from security scanners that use tar while still being extracted by downstream tools, enabling archive smuggling. The fix restricts PAX size overrides to recognised filesystem entry types via an allowlist.
You are affected if you are using a version that falls within the vulnerable range.
tar is vulnerable to Interpretation Conflict in versions 0.0.1 - 7.5.15.
Upgrade the tar library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant