cbcvebase.
CVE-2026-59875
published 2026-07-08

CVE-2026-59875: node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX path and linkpath records in…

PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.29%
21.2th percentile
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX path and linkpath records in src/pax.ts, allowing a crafted archive with values to reach fs.lstat or fs.open and terminate the process with an uncaught exception. This issue is fixed in version 7.5.17.

Affected

71 ranges· showing 25
VendorProductVersion rangeFixed in
3scale-amp2system-rhel7
3scale-amp2system-rhel8
3scale-amp2system-rhel9
3scale-amp21system
3scale-amp22system
ansible-automation-platformautomation-portal
ansible-automation-platformbootc-automation-portal-rhel9
devspacescode-rhel9
devspacesdashboard-rhel9
devspacesopenvsx-rhel9
devspacesudi-rhel9
exploit-intelligence-tech-previewvulnerability-analysis-rhel9
gnutar
gnutar>= 0 < 7.5.177.5.17
grafanagrafana
isaacsnode-tar< 7.5.177.5.17
nodejsnodejs
nodejs_22nodejs
nodejs_24nodejs
odf4mcg-core-rhel9
odf4ocs-client-console-rhel9
odf4odf-console-rhel9
odf4odf-multicluster-console-rhel9
openshift-pipelinespipelines-console-plugin-pf5-rhel9
openshift-pipelinespipelines-console-plugin-rhel8

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.