CVE-2026-59874

HIGH

node-tar: Negative tar entry size causes infinite loop in archive replace

Title source: cna
STIX 2.1

Description

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed in version 7.5.18.

Scores

CVSS v3 7.5
EPSS 0.0042
EPSS Percentile 34.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-835
Status published
Products (3)
isaacs/node-tar < 7.5.18
isaacs/tar < 7.5.18
npm/tar 0 - 7.5.18npm
Published Jul 08, 2026
Tracked Since Jul 08, 2026