Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

node-tar — Vulnerabilities & Security Advisories 19

All 19 CVE vulnerabilities found in node-tar, with AI-generated Chinese analysis, references, and POCs.

This page catalogs security vulnerabilities identified in node-tar, a popular Node.js package used for working with tar archives, categorized under generic weakness types and tagged for easy navigation. It aggregates data regarding various security flaws, including improper input validation and path traversal issues, covering the period from the package's initial public release through the most recent disclosed incidents. By reviewing this compilation, users can systematically track vendor advisories related to specific versions, gain a deeper understanding of the underlying weakness classes that affect archival processing libraries, and lookup the comprehensive vulnerability history of node-tar to assess risk exposure. The information presented is derived from publicly available security databases and official patch notes, providing a centralized view of the product's security posture over time. This resource is intended for developers, security analysts, and system administrators who require accurate historical data to make informed decisions about dependency management and remediation efforts. It does not include private or unreleased vulnerabilities, focusing solely on verified and disclosed issues. The structure allows for efficient filtering by date, severity, and specific technical characteristics, ensuring that stakeholders can quickly identify relevant entries without sifting through unrelated noise. Maintaining an up-to-date record helps organizations mitigate risks associated with outdated or vulnerable software components in their deployment pipelines.

Vendor: npm

CVE ID Title CVSS Severity Published
CVE-2026-73566 node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection CWE-400 7.5 High 2026-08-13
CVE-2026-59871 node-tar: Process crash via PAX numeric path type confusion CWE-704 5.3 Medium 2026-07-08
CVE-2026-59874 node-tar: Negative tar entry size causes infinite loop in archive replace CWE-835 - - 2026-07-08
CVE-2026-59873 node-tar: Decompression/parse DoS via unlimited input CWE-770 - - 2026-07-08
CVE-2026-59875 node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records CWE-248 5.3 Medium 2026-07-08
CVE-2026-53655 node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling) CWE-436 - - 2026-06-22
CVE-2026-31802 node-tar Symlink Path Traversal via Drive-Relative Linkpath CWE-22 7.5AI High AI 2026-03-09
CVE-2026-29786 node-tar: Hardlink Path Traversal via Drive-Relative Linkpath CWE-22 8.2 High 2026-03-07
CVE-2026-26960 node-tar has Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in Extraction CWE-22 7.1 High 2026-02-20
CVE-2026-24842 node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal CWE-22 8.2 High 2026-01-28
CVE-2026-23950 node-tar has Race Condition in Path Reservations via Unicode Ligature Collisions on macOS APFS CWE-176 8.8 High 2026-01-20
CVE-2026-23745 node-tar Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization CWE-22 8.2 High 2026-01-16
CVE-2025-64118 node-tar vulnerable to race condition leading to uninitialized memory exposure CWE-362 5.3AI Medium AI 2025-10-30
CVE-2024-28863 node-tar vulnerable to denial of service while parsing a tar file due to lack of folders count validation CWE-400 6.5 Medium 2024-03-21
CVE-2021-37713 Arbitrary File Creation/Overwrite on Windows via insufficient relative path sanitization CWE-22 8.2 High 2021-08-31
CVE-2021-37712 Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links CWE-22 8.2 High 2021-08-31
CVE-2021-37701 Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links CWE-22 8.2 High 2021-08-31
CVE-2021-32804 Arbitrary File Creation/Overwrite due to insufficient absolute path sanitization CWE-22 8.2 High 2021-08-03
CVE-2021-32803 Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning CWE-22 8.2 High 2021-08-03

All 19 known CVE vulnerabilities affecting node-tar with full Chinese analysis, references, and POCs where available.