PT-2026-56494 · Npm+2 · Node-Tar+2

·

CVE-2026-59874

·

Published

2026-06-28

·

Updated

2026-08-18

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions node-tar versions prior to 7.5.18
Description The tar.replace function accepts a checksum-valid tar header containing a negative base-256 encoded entry size. This causes the archive scanner to enter a loop where it repeatedly parses the same header without making progress.
Recommendations Update to version 7.5.18.

Exploit

Fix

DoS

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:47057
ALSA-2026:47058
ALSA-2026:47059
ALSA-2026:47060
ALSA-2026:48033
ALSA-2026:48034
BDU:2026-09562
CVE-2026-59874
GHSA-8X88-C5MF-7J5W
RHSA-2026:47057
RHSA-2026:47058
RHSA-2026:47059
RHSA-2026:47060
RHSA-2026:52399
RHSA-2026:53298

Affected Products

Confluence
Rocky Linux
Node-Tar