Feed/CVE-2026-59874
CVE-2026-59874HIGHCVSS 7.5

CVE-2026-59874

Published Jul 8, 2026·Updated Jul 20, 2026

NVD Description

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed in version 7.5.18.

Affected Packages (1)

tarNPM
Fixed in = 7.5.17

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free