CVE-2026-32288

tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU sparse map" format.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*

History

25 Jul 2026, 10:10

Type Values Removed Values Added
Summary
  • (es) tar.Reader puede asignar una cantidad ilimitada de memoria al leer un archivo creado maliciosamente que contiene un gran número de regiones dispersas codificadas en el formato 'old GNU sparse map'.

17 Jun 2026, 10:35

Type Values Removed Values Added
References () https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU - Release Notes, Mailing List () https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU - Mailing List, Release Notes

16 Apr 2026, 19:08

Type Values Removed Values Added
CWE CWE-770
References () https://go.dev/cl/763766 - () https://go.dev/cl/763766 - Patch
References () https://go.dev/issue/78301 - () https://go.dev/issue/78301 - Issue Tracking
References () https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU - () https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU - Release Notes, Mailing List
References () https://pkg.go.dev/vuln/GO-2026-4869 - () https://pkg.go.dev/vuln/GO-2026-4869 - Vendor Advisory
First Time Golang go
Golang
CPE cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*

13 Apr 2026, 19:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5

08 Apr 2026, 02:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-08 02:16

Updated : 2026-07-25 10:10


NVD link : CVE-2026-32288

Mitre link : CVE-2026-32288

CVE.ORG link : CVE-2026-32288


JSON object : View

Products Affected

golang

  • go
CWE
CWE-770

Allocation of Resources Without Limits or Throttling