CVE-2026-59874
HIGHnode-tar: Negative tar entry size causes infinite loop in archive replace
Title source: cnaDescription
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed in version 7.5.18.
References (3)
Core 3
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/isaacs/node-tar/security/advisories/GHSA-8x88-c5mf-7j5w
X_Refsource_Misc x_refsource_misc
https://github.com/isaacs/node-tar/commit/9e78bf058b2c22dd4d52e00d8922d5c06fc2f7b5
X_Refsource_Misc x_refsource_misc
https://github.com/isaacs/node-tar/releases/tag/v7.5.18
Scores
CVSS v3
7.5
EPSS
0.0042
EPSS Percentile
34.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-835
Status
published
Products (3)
isaacs/node-tar
< 7.5.18
isaacs/tar
< 7.5.18
npm/tar
0 - 7.5.18npm
Published
Jul 08, 2026
Tracked Since
Jul 08, 2026