cbcvebase.
CVE-2026-59874
published 2026-07-08

CVE-2026-59874: node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded…

PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.36%
28.2th percentile
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed in version 7.5.18.

Affected

59 ranges· showing 25
VendorProductVersion rangeFixed in
3scale-amp2system-rhel7
3scale-amp2system-rhel8
3scale-amp2system-rhel9
3scale-amp21system
3scale-amp22system
ansible-automation-platformautomation-portal
ansible-automation-platformbootc-automation-portal-rhel9
debianpython-cryptography
devspacescode-rhel9
devspacesdashboard-rhel9
devspacesopenvsx-rhel9
devspacesudi-rhel9
exploit-intelligence-tech-previewvulnerability-analysis-rhel9
gnutar
gnutar>= 0 < 7.5.187.5.18
grafanagrafana
isaacsnode-tar< 7.5.187.5.18
isaacstar< 7.5.187.5.18
nodejsnodejs
nodejs_22nodejs
nodejs_24nodejs
odf4mcg-core-rhel9
odf4ocs-client-console-rhel9
odf4odf-console-rhel9
odf4odf-multicluster-console-rhel9

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat8.7HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.