A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.
History

Sun, 12 Apr 2026 06:30:00 +0000

Type Values Removed Values Added
References

Sun, 12 Apr 2026 01:30:00 +0000

Type Values Removed Values Added
References

Sat, 11 Apr 2026 19:30:00 +0000

Type Values Removed Values Added
References

Thu, 09 Apr 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat hummingbird
CPEs cpe:/a:redhat:hummingbird:1
Vendors & Products Redhat hummingbird

Tue, 07 Apr 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 07 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 06 Apr 2026 15:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.
Title Tar: tar: hidden file injection via crafted archives
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-434
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2026-04-06T15:17:27.945Z

Updated: 2026-04-12T04:57:27.544Z

Reserved: 2026-04-06T13:37:17.528Z

Link: CVE-2026-5704

cve-icon Vulnrichment

Updated: 2026-04-11T18:09:35.974Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-06T16:16:42.140

Modified: 2026-04-12T06:16:21.607

Link: CVE-2026-5704

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-04-06T13:36:20Z

Links: CVE-2026-5704 - Bugzilla