Executive brief
A vulnerability in the Go programming language's standard library for handling TAR archives could allow an attacker to crash an application. By providing a specially crafted archive file, an attacker can force the program to consume all available system memory. This can lead to a denial-of-service, impacting the availability of services that process user-uploaded files.
Technical details
A resource exhaustion vulnerability exists in the archive/tar package of the Go standard library. The Reader.Next and related internal functions (readOldGNUSparseMap) fail to properly limit the number of sparse regions when parsing archives in the 'old GNU sparse map' format. An attacker can exploit this by providing a crafted TAR file with an excessive number of sparse entries, leading to unbounded memory allocation and a subsequent crash (Denial of Service). The fix introduces limits on the number of sparse map extension blocks and total sparse file entries. Patches are available in Go versions 1.25.9 and 1.26.2.
Affected products
- Go archive/tar (Go Standard Library) < 1.25.9, >= 1.26.0-0 < 1.26.2
Timeline
- 2026-03-23: disclosed: Issue opened in Go repository
- 2026-04-07: advisory: NVD and Go vulnerability reports published
- 2026-04-07: patched: Fixes released in Go 1.25.9 and 1.26.2