CVE-2026-59874
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed in version 7.5.18.
- Published Jul 8, 2026
- CVSS 8.7 high
- 0.6% chance of exploitation in the next 30 days (EPSS)
- Public exploit code is available
- A fix is available
Affected software
In the news
- Multiple vulnerabilities in IBM products CERT-FR ·