PT-2026-56493 · Npm+2 · Node-Tar+2

·

CVE-2026-59873

·

Published

2026-06-28

·

Updated

2026-08-18

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
Name of the Vulnerable Software and Affected Versions node-tar versions prior to 7.5.19
Description Insufficient enforcement of hard upper bounds on total decompressed data, entry counts, or decompression ratio within extraction and parsing paths, such as src/extract.ts, allows a crafted gzip bomb to exhaust CPU and disk space. A gzip bomb is a highly compressed archive that expands to an enormous size when decompressed, leading to a denial of service.
Recommendations Update to version 7.5.19.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:47057
ALSA-2026:47058
ALSA-2026:47059
ALSA-2026:47060
ALSA-2026:48033
ALSA-2026:48034
BDU:2026-09563
CVE-2026-59873
GHSA-23HP-3JRH-7FPW
RHSA-2026:47057
RHSA-2026:47058
RHSA-2026:47059
RHSA-2026:47060
RHSA-2026:52399
RHSA-2026:53298

Affected Products

Confluence
Rocky Linux
Node-Tar