Microsoft Security Response Center guidance
Vendor revision: Oct 7, 2026Release Notes
Vulnerability intelligence
CVE-2026-105712 and is rated Low severity with a CVSS score of 3.6. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
Release Notes
gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk.
Source: NVD