Skip to main content

Vendor/product archive

isaacs / tar CVEs

Beta · best-effort

12 CVEs tagged to isaacs / tar1 Critical, 8 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2026-59874

Published Jul 8, 2026

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing t…

CVSS 8.7 · High
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-59873

Published Jul 8, 2026

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression…

CVSS 9.2 · Critical
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-59871

Published Jul 8, 2026

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and linkpath values in src/pax.ts to JavaScript numbers, causing d…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-53655

Published Jun 22, 2026

node-tar is a full-featured Tar for Node.js. Prior to 7.5.16, tar (node-tar) applies a PAX extended header's size= record (and other PAX overrides) to the next header entry of any…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-31802

Published Mar 10, 2026

node-tar is a full-featured Tar for Node.js. Prior to version 7.5.11, tar (npm) can be tricked into creating a symlink that points outside the extraction directory by using a driv…

CVSS 8.2 · High
evidence mentions
2
Buzz score
21.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-29786

Published Mar 7, 2026

node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction directory by using a drive-rel…

CVSS 8.2 · High
evidence mentions
5
Buzz score
30.9
Vendor/product tagsBeta · best-effort

CVE-2026-26960

Published Feb 20, 2026

node-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-controlled archive can create a hardlink inside the extraction dir…

CVSS 7.1 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-24842

Published Jan 28, 2026

node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the act…

CVSS 8.2 · High
evidence mentions
11
Buzz score
37.9
Vendor/product tagsBeta · best-effort

CVE-2026-23950

Published Jan 20, 2026

node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path…

CVSS 8.8 · High
evidence mentions
10
Buzz score
37.0
Vendor/product tagsBeta · best-effort

CVE-2026-23745

Published Jan 16, 2026

node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries when preservePaths is false (the default…

CVSS 8.2 · High
evidence mentions
14
Buzz score
40.1
Vendor/product tagsBeta · best-effort

CVE-2024-28863

Published Mar 21, 2024

node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no limit on the number of sub-folders created in the folder creation process. An attacker who generates a large…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20834

Published Apr 30, 2019

A vulnerability was found in node-tar before version 4.4.2 (excluding version 2.2.2). An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1