Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-59875

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 5.3

Описание

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX path and linkpath records in src/pax.ts, allowing a crafted archive with values to reach fs.lstat or fs.open and terminate the process with an uncaught exception. This issue is fixed in version 7.5.17.

A flaw was found in node-tar, a library for manipulating tar archives in Node.js. A remote attacker could craft a malicious archive containing null characters (NUL bytes) in its metadata. When this archive is processed, the unstripped null characters can cause the application to terminate unexpectedly, leading to a Denial of Service (DoS).

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Confidential Compute Attestationopenshift-sandboxed-containers/osc-pccsFix deferred
Cryostat 4cryostat-openshift-console-plugin-npmFix deferred
Cryostat 4grafana-infinity-datasource-npmFix deferred
Cryostat 4tarFix deferred
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Fix deferred
Migration Toolkit for Containersrhmtc/openshift-migration-ui-rhel8Fix deferred
Node HealthCheck Operatorworkload-availability/node-healthcheck-must-gather-rhel9Fix deferred
Node HealthCheck Operatorworkload-availability/node-healthcheck-operator-bundleFix deferred
Node HealthCheck Operatorworkload-availability/node-healthcheck-rhel9-operatorFix deferred
OpenShift Pipelinesopenshift-pipelines/pipelines-console-plugin-pf5-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-170
https://bugzilla.redhat.com/show_bug.cgi?id=2498115node-tar: node-tar: Denial of Service via crafted archive with NUL bytes in metadata

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
24 дня назад

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX path and linkpath records in src/pax.ts, allowing a crafted archive with values to reach fs.lstat or fs.open and terminate the process with an uncaught exception. This issue is fixed in version 7.5.17.

CVSS3: 5.3
nvd
24 дня назад

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX path and linkpath records in src/pax.ts, allowing a crafted archive with values to reach fs.lstat or fs.open and terminate the process with an uncaught exception. This issue is fixed in version 7.5.17.

msrc
18 дней назад

node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records

CVSS3: 5.3
debian
24 дня назад

node-tar is a tar archive manipulation library for Node.js. Prior to 7 ...

CVSS3: 5.3
github
12 дней назад

node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records

5.3 Medium

CVSS3