There's a CVE for all tar versions <7.5.3: https://www.cvedetails.com/cve/CVE-2026-23745/ I see PR #234 suggests removing the tar dependency, that would of course solve the issue as well.