GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. (CVE-2025-45582) Tar: toctou in incremental dumpdir 'x' rename handling allows restore path escape. (CVE-2026-18477) Tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite. (CVE-2026-18508)