CVE WATCH / VULNERABILITY DETAIL

CVE-2026-105712

LOWCVSS 3.6NVD feed

Published 5 October 2026 · tracked since 6 October 2026

Description

gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extra

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-105712 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-105712

LOWCVSS 3.6NVD feed

Published 5 October 2026 · tracked since 6 October 2026

Description

gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extra

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]