Количество 9
Количество 9
GHSA-8x88-c5mf-7j5w
node-tar: Negative tar entry size causes infinite loop in archive replace
CVE-2026-59874
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed in version 7.5.18.
CVE-2026-59874
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed in version 7.5.18.
CVE-2026-59874
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed in version 7.5.18.
CVE-2026-59874
node-tar: Negative tar entry size causes infinite loop in archive replace
CVE-2026-59874
node-tar is a tar archive manipulation library for Node.js. Prior to 7 ...
BDU:2026-09562
Уязвимость функции tar.replace() библиотеки node-tar программной платформы Node.js, позволяющая нарушителю вызвать отказ в обслуживании
RLSA-2026:47060
Important: nodejs:24 security update
RLSA-2026:47059
Important: nodejs:22 security update
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-8x88-c5mf-7j5w node-tar: Negative tar entry size causes infinite loop in archive replace | CVSS3: 7.5 | 0% Низкий | 12 дней назад | |
CVE-2026-59874 node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed in version 7.5.18. | CVSS3: 7.5 | 0% Низкий | 25 дней назад | |
CVE-2026-59874 node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed in version 7.5.18. | CVSS3: 7.5 | 0% Низкий | 25 дней назад | |
CVE-2026-59874 node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed in version 7.5.18. | CVSS3: 7.5 | 0% Низкий | 25 дней назад | |
CVE-2026-59874 node-tar: Negative tar entry size causes infinite loop in archive replace | 0% Низкий | 21 день назад | ||
CVE-2026-59874 node-tar is a tar archive manipulation library for Node.js. Prior to 7 ... | CVSS3: 7.5 | 0% Низкий | 25 дней назад | |
BDU:2026-09562 Уязвимость функции tar.replace() библиотеки node-tar программной платформы Node.js, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
RLSA-2026:47060 Important: nodejs:24 security update | 5 дней назад | |||
RLSA-2026:47059 Important: nodejs:22 security update | 4 дня назад |
Уязвимостей на страницу