CVE-2026-5704

MEDIUM WAF: Medium
CVSS 5.5 Published: 2026-04-06
CWE-434

A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.

WAF Coverage Analysis

Unrestricted File Upload Medium WAF Coverage

OWASP: A04:2021 Insecure Design

930xxx - Local File Inclusion

Affected Software

VendorProductVersion
gnutar-
redhathardened_images-
redhatenterprise_linux6.0
redhatenterprise_linux7.0
redhatenterprise_linux8.0
redhatenterprise_linux9.0
redhatenterprise_linux10.0

References

Back to CVE Database