CVE-2026-59873

Updated on 08 Jul 2026

Severity

9.2 Critical severity

Details

CVSS score
9.2
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Overview

About vulnerability

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19.

Details

Affected product:
AlmaLinux 9.2 ESU , Alpine Linux 3.18 ELS , Amazon Linux 2 ELS , Angular , AngularJS , CentOS 6 ELS , CentOS 7 ELS , CentOS 8.4 ELS , CentOS 8.5 ELS , CentOS Stream 8 ELS , CloudLinux 7 ELS , Debian 10 ELS , Debian 11 ELS , Next.js , Node.js , Oracle Linux 6 ELS , Oracle Linux 7 ELS , RHEL 7 ELS , React , TuxCare 9.6 ESU , Ubuntu 16.04 ELS , Ubuntu 18.04 ELS , Ubuntu 20.04 ELS , adk-js , apollo-gateway , apollo-server-plugin-operation-registry , berry , build , c12 , cacache , celo-celocli , celo-connect , celo-contractkit , celo-dev-utils , celo-encrypted-backup , celo-explorer , celo-governance , celo-identity , celo-phone-number-privacy-common , cli , codesmith , copy-webpack-plugin , developer-tooling , duckdb-node , ember-cli , expo , facebook-create-react-app , giget , graphql-hive-envelop , graphql-mesh , graphql-yoga , grpc-node , guess , ionic-cli , jovidecroock-prefresh , jsdom , libcipm , libnpm , libnpmversion , make-fetch-happen , medplum , mikro-orm , minimizer-webpack-plugin , netlify-build , netlify-dev , netlify-functions-utils , netlify/functions , nft , nguniversal , npm , npm-lifecycle , npm-profile , npm-registry-fetch , npm:libnpmpack , npmcli-arborist , npmcli-metavuln-calculator , nuxt , opencensus-node , pacote , pdfjs-dist , protractor , remix , run-script , sigstore-js , sqlite3 , storybook , swarm-js , tar , tar-pack , telemetry , ts-evaluator , tuf-js , tuql , vercel , web3.js , webdriver-manager , webpack , webpack-cli-generators , yarnpkg-plugin-compat , yarnpkg-plugin-npm-cli , yarnpkg-plugin-pnp , yarnpkg-sdks , yeoman-generator , yeoman/environment
Affected packages:
@angular/ssr @ 19.2.25 (+729 more)

Fixes