CVE-2026-59873
published 2026-07-08CVE-2026-59873: node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.36%
28.3th percentile
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19.
Affected
59 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| 3scale-amp2 | system-rhel7 | — | — |
| 3scale-amp2 | system-rhel8 | — | — |
| 3scale-amp2 | system-rhel9 | — | — |
| 3scale-amp21 | system | — | — |
| 3scale-amp22 | system | — | — |
| ansible-automation-platform | automation-portal | — | — |
| ansible-automation-platform | bootc-automation-portal-rhel9 | — | — |
| debian | python-cryptography | — | — |
| devspaces | code-rhel9 | — | — |
| devspaces | dashboard-rhel9 | — | — |
| devspaces | openvsx-rhel9 | — | — |
| devspaces | udi-rhel9 | — | — |
| exploit-intelligence-tech-preview | vulnerability-analysis-rhel9 | — | — |
| gnu | tar | — | — |
| gnu | tar | >= 0 < 7.5.19 | 7.5.19 |
| grafana | grafana | — | — |
| isaacs | node-tar | < 7.5.19 | 7.5.19 |
| isaacs | tar | < 7.5.19 | 7.5.19 |
| nodejs | nodejs | — | — |
| nodejs_22 | nodejs | — | — |
| nodejs_24 | nodejs | — | — |
| odf4 | mcg-core-rhel9 | — | — |
| odf4 | ocs-client-console-rhel9 | — | — |
| odf4 | odf-console-rhel9 | — | — |
| odf4 | odf-multicluster-console-rhel9 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.09.2CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat9.2CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
node-tar: Decompression/parse DoS via unlimited input
ghsa·2026-07-20
CVE-2026-59873 [CRITICAL] CWE-770 node-tar: Decompression/parse DoS via unlimited input
node-tar: Decompression/parse DoS via unlimited input
### Summary
A **Decompression/parse DoS via unlimited input** vulnerability in `node-tar` allows an attacker to exhaust server resources (disk space and CPU). Because the library does not enforce hard upper bounds on total decompressed data or entry counts, a small, maliciously crafted "Gzip Bomb" can be used to fill a server's storage and crash services.
### Details
The `node-tar` library does not enforce a hard upper bound on archive size or the volume of decompressed data processed during extraction. While the `maxReadSize` option exists, it only controls internal read chunk sizes (default 16MB) and does not limit the total cumulative bytes written to disk.
Specifically, in `src/extract.ts`, the `Unpack` stream processes entries a
VulDB
isaacs node-tar up to 7.5.18 Decompression src/extract.ts memory corruption
vuldb·2026-07-12·CVSS 7.5
CVE-2026-59873 [HIGH] isaacs node-tar up to 7.5.18 Decompression src/extract.ts memory corruption
A vulnerability classified as problematic has been found in isaacs node-tar up to 7.5.18. This vulnerability affects unknown code of the file src/extract.ts of the component Decompression. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2026-59873. The attack is possible to be carried out remotely. No exploit exists.
Red Hat
tar: node-tar: Denial of Service via crafted gzip bomb
vendor_redhat·2026-07-08·CVSS 9.2
CVE-2026-59873 [CRITICAL] CWE-770 tar: node-tar: Denial of Service via crafted gzip bomb
tar: node-tar: Denial of Service via crafted gzip bomb
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19.
A flaw was found in node-tar, a tar archive manipulation library for Node.js. This vulnerability allows a remote attacker to craft a small gzip bomb, which, when processed, can lead to the exhaustion of disk space and CPU resources. This occurs because node-tar does not enforce strict limits on the total decompressed data, the number of entries, or the decompression ratio during extraction and
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-59873 nodejs22: node-tar: Denial of Service via crafted gzip bomb [fedora-all]
bugzilla·2026-07-09·CVSS 9.2
CVE-2026-59873 [CRITICAL] CVE-2026-59873 nodejs22: node-tar: Denial of Service via crafted gzip bomb [fedora-all]
CVE-2026-59873 nodejs22: node-tar: Denial of Service via crafted gzip bomb [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19.
Bugzilla
CVE-2026-59873 tar: node-tar: Denial of Service via crafted gzip bomb [fedora-all]
bugzilla·2026-07-09·CVSS 9.2
CVE-2026-59873 [CRITICAL] CVE-2026-59873 tar: node-tar: Denial of Service via crafted gzip bomb [fedora-all]
CVE-2026-59873 tar: node-tar: Denial of Service via crafted gzip bomb [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19.
Bugzilla
CVE-2026-59873 openbao: node-tar: Denial of Service via crafted gzip bomb [epel-all]
bugzilla·2026-07-09·CVSS 9.2
CVE-2026-59873 [CRITICAL] CVE-2026-59873 openbao: node-tar: Denial of Service via crafted gzip bomb [epel-all]
CVE-2026-59873 openbao: node-tar: Denial of Service via crafted gzip bomb [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19.
Bugzilla
CVE-2026-59873 kf6-breeze-icons: node-tar: Denial of Service via crafted gzip bomb [epel-all]
bugzilla·2026-07-09·CVSS 9.2
CVE-2026-59873 [CRITICAL] CVE-2026-59873 kf6-breeze-icons: node-tar: Denial of Service via crafted gzip bomb [epel-all]
CVE-2026-59873 kf6-breeze-icons: node-tar: Denial of Service via crafted gzip bomb [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19.
Bugzilla
CVE-2026-59873 sgx-pccs: node-tar: Denial of Service via crafted gzip bomb [fedora-all]
bugzilla·2026-07-09·CVSS 9.2
CVE-2026-59873 [CRITICAL] CVE-2026-59873 sgx-pccs: node-tar: Denial of Service via crafted gzip bomb [fedora-all]
CVE-2026-59873 sgx-pccs: node-tar: Denial of Service via crafted gzip bomb [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19.
Bugzilla
CVE-2026-59873 openbao: node-tar: Denial of Service via crafted gzip bomb [fedora-all]
bugzilla·2026-07-09·CVSS 9.2
CVE-2026-59873 [CRITICAL] CVE-2026-59873 openbao: node-tar: Denial of Service via crafted gzip bomb [fedora-all]
CVE-2026-59873 openbao: node-tar: Denial of Service via crafted gzip bomb [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19.
Bugzilla
CVE-2026-59873 nodejs20: node-tar: Denial of Service via crafted gzip bomb [fedora-all]
bugzilla·2026-07-09·CVSS 9.2
CVE-2026-59873 [CRITICAL] CVE-2026-59873 nodejs20: node-tar: Denial of Service via crafted gzip bomb [fedora-all]
CVE-2026-59873 nodejs20: node-tar: Denial of Service via crafted gzip bomb [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19.
Bugzilla
CVE-2026-59873 openvino: node-tar: Denial of Service via crafted gzip bomb [fedora-all]
bugzilla·2026-07-09·CVSS 9.2
CVE-2026-59873 [CRITICAL] CVE-2026-59873 openvino: node-tar: Denial of Service via crafted gzip bomb [fedora-all]
CVE-2026-59873 openvino: node-tar: Denial of Service via crafted gzip bomb [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19.
Bugzilla
CVE-2026-59873 crow-translate: node-tar: Denial of Service via crafted gzip bomb [fedora-all]
bugzilla·2026-07-09·CVSS 9.2
CVE-2026-59873 [CRITICAL] CVE-2026-59873 crow-translate: node-tar: Denial of Service via crafted gzip bomb [fedora-all]
CVE-2026-59873 crow-translate: node-tar: Denial of Service via crafted gzip bomb [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19.
Bugzilla
CVE-2026-59873 yarnpkg: node-tar: Denial of Service via crafted gzip bomb [fedora-all]
bugzilla·2026-07-09·CVSS 9.2
CVE-2026-59873 [CRITICAL] CVE-2026-59873 yarnpkg: node-tar: Denial of Service via crafted gzip bomb [fedora-all]
CVE-2026-59873 yarnpkg: node-tar: Denial of Service via crafted gzip bomb [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19.
Bugzilla
CVE-2026-59873 yarnpkg: node-tar: Denial of Service via crafted gzip bomb [epel-all]
bugzilla·2026-07-09·CVSS 9.2
CVE-2026-59873 [CRITICAL] CVE-2026-59873 yarnpkg: node-tar: Denial of Service via crafted gzip bomb [epel-all]
CVE-2026-59873 yarnpkg: node-tar: Denial of Service via crafted gzip bomb [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19.
Bugzilla
CVE-2026-59873 kf6-breeze-icons: node-tar: Denial of Service via crafted gzip bomb [fedora-all]
bugzilla·2026-07-09·CVSS 9.2
CVE-2026-59873 [CRITICAL] CVE-2026-59873 kf6-breeze-icons: node-tar: Denial of Service via crafted gzip bomb [fedora-all]
CVE-2026-59873 kf6-breeze-icons: node-tar: Denial of Service via crafted gzip bomb [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19.
Bugzilla
CVE-2026-59873 mozjs78: node-tar: Denial of Service via crafted gzip bomb [epel-all]
bugzilla·2026-07-09·CVSS 9.2
CVE-2026-59873 [CRITICAL] CVE-2026-59873 mozjs78: node-tar: Denial of Service via crafted gzip bomb [epel-all]
CVE-2026-59873 mozjs78: node-tar: Denial of Service via crafted gzip bomb [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19.
Bugzilla
CVE-2026-59873 nodejs24: node-tar: Denial of Service via crafted gzip bomb [fedora-all]
bugzilla·2026-07-09·CVSS 9.2
CVE-2026-59873 [CRITICAL] CVE-2026-59873 nodejs24: node-tar: Denial of Service via crafted gzip bomb [fedora-all]
CVE-2026-59873 nodejs24: node-tar: Denial of Service via crafted gzip bomb [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19.
Bugzilla
CVE-2026-59873 onnxruntime: node-tar: Denial of Service via crafted gzip bomb [fedora-all]
bugzilla·2026-07-09·CVSS 9.2
CVE-2026-59873 [CRITICAL] CVE-2026-59873 onnxruntime: node-tar: Denial of Service via crafted gzip bomb [fedora-all]
CVE-2026-59873 onnxruntime: node-tar: Denial of Service via crafted gzip bomb [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19.
Bugzilla
CVE-2026-59873 tar: node-tar: Denial of Service via crafted gzip bomb
bugzilla·2026-07-08·CVSS 9.2
CVE-2026-59873 [CRITICAL] CVE-2026-59873 tar: node-tar: Denial of Service via crafted gzip bomb
CVE-2026-59873 tar: node-tar: Denial of Service via crafted gzip bomb
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19.
2026-07-08
Published