CVE-2026-32288: Golang Go
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU sparse map" format.
Affected products
- Golang Go: before 1.25.9 (fixed in 1.25.9); from 1.26.0, before 1.26.2 (fixed in 1.26.2)
Published 2026-04-08. Last modified 2026-07-25.