Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

node-tar — Vulnerabilities & Security Advisories 19

All 19 CVE vulnerabilities found in node-tar, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities associated with the npm package node-tar, specifically focusing on the software product maintained within the Node.js ecosystem. It collects documented defects including path traversal, symlink attacks, and arbitrary code execution flaws recorded across multiple release versions of the library. The data covers advisories published over a multi-year period, reflecting the ongoing history of security patches and bug fixes for this widely used archiving tool. Readers can use this hub to track vendor-issued advisories, understand the specific weakness classes affecting the package, and review the chronological vulnerability history for node-tar. The compilation serves as a reference for developers and security teams who need to audit dependencies, assess risk, and verify that their installations include the latest mitigations. By centralizing these records, the page helps users move beyond isolated CVE lookups to grasp the broader pattern of how security issues have evolved within this particular software artifact.

Vendor: npm

CVE ID Title CVSS Severity Published
CVE-2026-73566 node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection CWE-400 7.5 High 2026-08-13
CVE-2026-59871 node-tar: Process crash via PAX numeric path type confusion CWE-704 5.3 Medium 2026-07-08
CVE-2026-59874 node-tar: Negative tar entry size causes infinite loop in archive replace CWE-835 - - 2026-07-08
CVE-2026-59873 node-tar: Decompression/parse DoS via unlimited input CWE-770 - - 2026-07-08
CVE-2026-59875 node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records CWE-248 5.3 Medium 2026-07-08
CVE-2026-53655 node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling) CWE-436 - - 2026-06-22
CVE-2026-31802 node-tar Symlink Path Traversal via Drive-Relative Linkpath CWE-22 7.5AI High AI 2026-03-09
CVE-2026-29786 node-tar: Hardlink Path Traversal via Drive-Relative Linkpath CWE-22 8.2 High 2026-03-07
CVE-2026-26960 node-tar has Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in Extraction CWE-22 7.1 High 2026-02-20
CVE-2026-24842 node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal CWE-22 8.2 High 2026-01-28
CVE-2026-23950 node-tar has Race Condition in Path Reservations via Unicode Ligature Collisions on macOS APFS CWE-176 8.8 High 2026-01-20
CVE-2026-23745 node-tar Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization CWE-22 8.2 High 2026-01-16
CVE-2025-64118 node-tar vulnerable to race condition leading to uninitialized memory exposure CWE-362 5.3AI Medium AI 2025-10-30
CVE-2024-28863 node-tar vulnerable to denial of service while parsing a tar file due to lack of folders count validation CWE-400 6.5 Medium 2024-03-21
CVE-2021-37713 Arbitrary File Creation/Overwrite on Windows via insufficient relative path sanitization CWE-22 8.2 High 2021-08-31
CVE-2021-37712 Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links CWE-22 8.2 High 2021-08-31
CVE-2021-37701 Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links CWE-22 8.2 High 2021-08-31
CVE-2021-32804 Arbitrary File Creation/Overwrite due to insufficient absolute path sanitization CWE-22 8.2 High 2021-08-03
CVE-2021-32803 Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning CWE-22 8.2 High 2021-08-03

All 19 known CVE vulnerabilities affecting node-tar with full Chinese analysis, references, and POCs where available.