VYPR
High severity7.5OSV Advisory· Published Jul 8, 2026· Updated Jul 10, 2026

CVE-2026-59874

CVE-2026-59874

Description

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed in version 7.5.18.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
tarnpm
< 7.5.187.5.18

Affected products

58

Patches

Vulnerability mechanics

References

5

News mentions

1