CVE-2026-21436: Tar Member Missing Manifest Check
Processing tar members and normalizing paths without validating them against an expected manifest (allowlist). This can lead to the handling of unlisted files and arbitrary file creation via path traversal payloads should the archive be compromised. Validation against a safe list is necessary.
greprules fetch cve-2026-21436-tar-member-missing-manifest-check --engine opengrepDescription
Processing tar members and normalizing paths without validating them against an expected manifest (allowlist). This can lead to the handling of unlisted files and arbitrary file creation via path traversal payloads should the archive be compromised. Validation against a safe list is necessary.
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.