Node-Tar

Isaacs · 14 CVEs

CVE-2026-73566
HIGH

node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar…

Aug 13, 2026

CVE-2026-59871
HIGH

node-tar: Process crash via PAX numeric path type confusion

Jul 8, 2026

CVE-2026-59874
HIGH

node-tar: Negative tar entry size causes infinite loop in archive replace

Jul 8, 2026

CVE-2026-59873
CRITICAL

node-tar: Decompression/parse DoS via unlimited input

Jul 8, 2026

CVE-2026-59875
MEDIUM

node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records

Jul 8, 2026

CVE-2026-53655
MEDIUM

node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation d…

Jun 22, 2026

CVE-2026-31802
HIGH

node-tar Symlink Path Traversal via Drive-Relative Linkpath

Mar 9, 2026

CVE-2026-29786
HIGH

node-tar: Hardlink Path Traversal via Drive-Relative Linkpath

Mar 7, 2026

CVE-2026-26960
HIGH

node-tar has Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in Extraction

Feb 20, 2026

CVE-2026-24842
HIGH

node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal

Jan 28, 2026

CVE-2026-23950
HIGH

node-tar has Race Condition in Path Reservations via Unicode Ligature Collisions on macOS APFS

Jan 20, 2026

CVE-2026-23745
HIGH

node-tar Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization

Jan 16, 2026

CVE-2025-64118
MEDIUM

node-tar vulnerable to race condition leading to uninitialized memory exposure

Oct 30, 2025

CVE-2024-28863
MEDIUM

node-tar vulnerable to denial of service while parsing a tar file due to lack of folders count validation

Mar 21, 2024

Showing 1 to 14 of 14 CVEs