CVE-2026-59875

MEDIUM

node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records

Title source: cna
STIX 2.1

Description

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX path and linkpath records in src/pax.ts, allowing a crafted archive with values to reach fs.lstat or fs.open and terminate the process with an uncaught exception. This issue is fixed in version 7.5.17.

Scores

CVSS v3 5.3
EPSS 0.0029
EPSS Percentile 21.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-248
Status published
Products (2)
isaacs/node-tar < 7.5.17
npm/tar 0 - 7.5.17npm
Published Jul 08, 2026
Tracked Since Jul 08, 2026