« Volver al listado

CVE-2026-32288

Estado: AnalizadaMedia (5.5)—

tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU sparse map" format.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-32288",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-32288",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-04-13T17:51:05.649111Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@golang.org",
      "affectedData": [
        {
          "vendor": "Go standard library",
          "product": "archive/tar",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.25.9",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "1.26.0-0",
              "lessThan": "1.26.2",
              "versionType": "semver"
            }
          ],
          "packageName": "archive/tar",
          "collectionURL": "https://pkg.go.dev",
          "defaultStatus": "unaffected",
          "programRoutines": [
            {
              "name": "Reader.readOldGNUSparseMap"
            },
            {
              "name": "readGNUSparseMap1x0"
            },
            {
              "name": "Reader.Next"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-04-08T02:16:03.707",
  "references": [
    {
      "url": "https://go.dev/cl/763766",
      "tags": [
        "Patch"
      ],
      "source": "security@golang.org"
    },
    {
      "url": "https://go.dev/issue/78301",
      "tags": [
        "Issue Tracking"
      ],
      "source": "security@golang.org"
    },
    {
      "url": "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU",
      "tags": [
        "Mailing List",
        "Release Notes"
      ],
      "source": "security@golang.org"
    },
    {
      "url": "https://pkg.go.dev/vuln/GO-2026-4869",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@golang.org"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-770"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the \"old GNU sparse map\" format."
    },
    {
      "lang": "es",
      "value": "tar.Reader puede asignar una cantidad ilimitada de memoria al leer un archivo creado maliciosamente que contiene un gran número de regiones dispersas codificadas en el formato 'old GNU sparse map'."
    }
  ],
  "lastModified": "2026-07-25T10:10:00.167",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C6C9C072-9817-402D-877F-F83584B07017",
              "versionEndExcluding": "1.25.9"
            },
            {
              "criteria": "cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "39FE9BAF-55E9-43AA-B14E-239E7EF1D65D",
              "versionEndExcluding": "1.26.2",
              "versionStartIncluding": "1.26.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@golang.org"
}