Node-Tar
Isaacs · 14 CVEs
node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar…
Aug 13, 2026
node-tar: Process crash via PAX numeric path type confusion
Jul 8, 2026
node-tar: Negative tar entry size causes infinite loop in archive replace
Jul 8, 2026
node-tar: Decompression/parse DoS via unlimited input
Jul 8, 2026
node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records
Jul 8, 2026
node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation d…
Jun 22, 2026
node-tar Symlink Path Traversal via Drive-Relative Linkpath
Mar 9, 2026
node-tar: Hardlink Path Traversal via Drive-Relative Linkpath
Mar 7, 2026
node-tar has Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in Extraction
Feb 20, 2026
node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal
Jan 28, 2026
node-tar has Race Condition in Path Reservations via Unicode Ligature Collisions on macOS APFS
Jan 20, 2026
node-tar Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization
Jan 16, 2026
node-tar vulnerable to race condition leading to uninitialized memory exposure
Oct 30, 2025
node-tar vulnerable to denial of service while parsing a tar file due to lack of folders count validation
Mar 21, 2024
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-73566 | node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection | HIGH | 0.53% | Aug 13, 2026 |
| CVE-2026-59871 | node-tar: Process crash via PAX numeric path type confusion | HIGH | 0.64% | Jul 8, 2026 |
| CVE-2026-59874 | node-tar: Negative tar entry size causes infinite loop in archive replace | HIGH | 0.64% | Jul 8, 2026 |
| CVE-2026-59873 | node-tar: Decompression/parse DoS via unlimited input | CRITICAL | 0.64% | Jul 8, 2026 |
| CVE-2026-59875 | node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records | MEDIUM | 0.51% | Jul 8, 2026 |
| CVE-2026-53655 | node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling) | MEDIUM | 0.16% | Jun 22, 2026 |
| CVE-2026-31802 | node-tar Symlink Path Traversal via Drive-Relative Linkpath | HIGH | 0.18% | Mar 9, 2026 |
| CVE-2026-29786 | node-tar: Hardlink Path Traversal via Drive-Relative Linkpath | HIGH | 0.40% | Mar 7, 2026 |
| CVE-2026-26960 | node-tar has Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in Extraction | HIGH | 0.20% | Feb 20, 2026 |
| CVE-2026-24842 | node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal | HIGH | 0.62% | Jan 28, 2026 |
| CVE-2026-23950 | node-tar has Race Condition in Path Reservations via Unicode Ligature Collisions on macOS APFS | HIGH | 0.26% | Jan 20, 2026 |
| CVE-2026-23745 | node-tar Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization | HIGH | 0.38% | Jan 16, 2026 |
| CVE-2025-64118 | node-tar vulnerable to race condition leading to uninitialized memory exposure | MEDIUM | 0.13% | Oct 30, 2025 |
| CVE-2024-28863 | node-tar vulnerable to denial of service while parsing a tar file due to lack of folders count validation | MEDIUM | 0.93% | Mar 21, 2024 |
Showing 1 to 14 of 14 CVEs