Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-59874

Опубликовано: 08 июл. 2026
Источник: debian

Описание

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed in version 7.5.18.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-tarfixed7.5.19+~4.0.1-1package
node-tarno-dsatrixiepackage
node-tarpostponedbookwormpackage
node-tarpostponedbullseyepackage

Примечания

  • https://github.com/isaacs/node-tar/security/advisories/GHSA-8x88-c5mf-7j5w

  • Fixed by: https://github.com/isaacs/node-tar/commit/9e78bf058b2c22dd4d52e00d8922d5c06fc2f7b5 (v7.5.18)

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed in version 7.5.18.

CVSS3: 7.5
redhat
3 месяца назад

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed in version 7.5.18.

CVSS3: 7.5
nvd
3 месяца назад

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed in version 7.5.18.

msrc
2 месяца назад

node-tar: Negative tar entry size causes infinite loop in archive replace

CVSS3: 7.5
github
2 месяца назад

node-tar: Negative tar entry size causes infinite loop in archive replace