CVE-2026-32288: Golang Go

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU sparse map" format.

Affected products

  • Golang Go: before 1.25.9 (fixed in 1.25.9); from 1.26.0, before 1.26.2 (fixed in 1.26.2)

Published 2026-04-08. Last modified 2026-07-25.