PT-2026-56493 · Npm+2 · Node-Tar+2
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H |
Name of the Vulnerable Software and Affected Versions
node-tar versions prior to 7.5.19
Description
Insufficient enforcement of hard upper bounds on total decompressed data, entry counts, or decompression ratio within extraction and parsing paths, such as
src/extract.ts, allows a crafted gzip bomb to exhaust CPU and disk space. A gzip bomb is a highly compressed archive that expands to an enormous size when decompressed, leading to a denial of service.Recommendations
Update to version 7.5.19.
Exploit
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Confluence
Rocky Linux
Node-Tar