Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 7

Количество 7

ubuntu логотип

CVE-2026-59873

22 дня назад

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-59873

22 дня назад

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-59873

22 дня назад

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2026-59873

19 дней назад

node-tar: Decompression/parse DoS via unlimited input

EPSS: Низкий
debian логотип

CVE-2026-59873

22 дня назад

node-tar is a tar archive manipulation library for Node.js. Prior to 7 ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-23hp-3jrh-7fpw

10 дней назад

node-tar: Decompression/parse DoS via unlimited input

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2026-09563

около 1 месяца назад

Уязвимость файла src/extract.ts библиотеки node-tar программной платформы Node.js, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 8.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-59873

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19.

CVSS3: 7.5
0%
Низкий
22 дня назад
redhat логотип
CVE-2026-59873

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19.

CVSS3: 7.5
0%
Низкий
22 дня назад
nvd логотип
CVE-2026-59873

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19.

CVSS3: 7.5
0%
Низкий
22 дня назад
msrc логотип
CVE-2026-59873

node-tar: Decompression/parse DoS via unlimited input

0%
Низкий
19 дней назад
debian логотип
CVE-2026-59873

node-tar is a tar archive manipulation library for Node.js. Prior to 7 ...

CVSS3: 7.5
0%
Низкий
22 дня назад
github логотип
GHSA-23hp-3jrh-7fpw

node-tar: Decompression/parse DoS via unlimited input

CVSS3: 7.5
0%
Низкий
10 дней назад
fstec логотип
BDU:2026-09563

Уязвимость файла src/extract.ts библиотеки node-tar программной платформы Node.js, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 8.6
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу