Isaacs / Tar
12 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-59871 | node-tar: Process crash via PAX numeric path type confusion | HIGH | 7.5 | Jul 8, 2026 |
| CVE-2026-59874 | node-tar: Negative tar entry size causes infinite loop in archive replace | HIGH | 8.7 | Jul 8, 2026 |
| CVE-2026-59873 | node-tar: Decompression/parse DoS via unlimited input | CRITICAL | 9.2 | Jul 8, 2026 |
| CVE-2026-53655 | node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling) | MEDIUM | 6.9 | Jun 22, 2026 |
| CVE-2026-31802 | node-tar Symlink Path Traversal via Drive-Relative Linkpath | HIGH | 8.2 | Mar 9, 2026 |
| CVE-2026-29786 | node-tar: Hardlink Path Traversal via Drive-Relative Linkpath | HIGH | 8.2 | Mar 7, 2026 |
| CVE-2026-26960 | node-tar has Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in Extraction | HIGH | 7.1 | Feb 20, 2026 |
| CVE-2026-24842 | node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal | HIGH | 8.2 | Jan 28, 2026 |
| CVE-2026-23950 | node-tar has Race Condition in Path Reservations via Unicode Ligature Collisions on macOS APFS | HIGH | 8.8 | Jan 20, 2026 |
| CVE-2026-23745 | node-tar Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization | HIGH | 8.2 | Jan 16, 2026 |
| CVE-2024-28863 | node-tar vulnerable to denial of service while parsing a tar file due to lack of folders count validation | MEDIUM | 6.5 | Mar 21, 2024 |
| CVE-2018-20834 | nodejs-tar: Arbitrary file overwrites when extracting tarballs containing a hard-link | HIGH | 8.8 | Apr 30, 2019 |
Showing 1 to 12 of 12 CVEs