
GNU tar desync lets archives inject hidden files on extract
An oss-security post highlights a GNU tar 1.35 mismatch where `tar -t` hides entries that `tar -x` writes, enabling hidden file injection (CVE-2026-5704).
NewsSupply ChainBuild Security
2 minYesterday
