Количество 6
Количество 6
CVE-2026-59871
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and linkpath values in src/pax.ts to JavaScript numbers, causing downstream path handling such as normalizeWindowsPath(entry.path).split('/') to throw an uncaught TypeError. This issue is fixed in version 7.5.18.
CVE-2026-59871
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and linkpath values in src/pax.ts to JavaScript numbers, causing downstream path handling such as normalizeWindowsPath(entry.path).split('/') to throw an uncaught TypeError. This issue is fixed in version 7.5.18.
CVE-2026-59871
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and linkpath values in src/pax.ts to JavaScript numbers, causing downstream path handling such as normalizeWindowsPath(entry.path).split('/') to throw an uncaught TypeError. This issue is fixed in version 7.5.18.
CVE-2026-59871
node-tar: Process crash via PAX numeric path type confusion
CVE-2026-59871
node-tar is a tar archive manipulation library for Node.js. Prior to 7 ...
GHSA-w8wr-v893-vjvp
node-tar: Process crash via PAX numeric path type confusion
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-59871 node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and linkpath values in src/pax.ts to JavaScript numbers, causing downstream path handling such as normalizeWindowsPath(entry.path).split('/') to throw an uncaught TypeError. This issue is fixed in version 7.5.18. | CVSS3: 5.3 | 0% Низкий | 25 дней назад | |
CVE-2026-59871 node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and linkpath values in src/pax.ts to JavaScript numbers, causing downstream path handling such as normalizeWindowsPath(entry.path).split('/') to throw an uncaught TypeError. This issue is fixed in version 7.5.18. | CVSS3: 5.3 | 0% Низкий | 25 дней назад | |
CVE-2026-59871 node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and linkpath values in src/pax.ts to JavaScript numbers, causing downstream path handling such as normalizeWindowsPath(entry.path).split('/') to throw an uncaught TypeError. This issue is fixed in version 7.5.18. | CVSS3: 5.3 | 0% Низкий | 25 дней назад | |
CVE-2026-59871 node-tar: Process crash via PAX numeric path type confusion | 0% Низкий | 21 день назад | ||
CVE-2026-59871 node-tar is a tar archive manipulation library for Node.js. Prior to 7 ... | CVSS3: 5.3 | 0% Низкий | 25 дней назад | |
GHSA-w8wr-v893-vjvp node-tar: Process crash via PAX numeric path type confusion | CVSS3: 5.3 | 0% Низкий | 12 дней назад |
Уязвимостей на страницу