cbcvebase.
CVE-2026-73566
published 2026-08-13

CVE-2026-73566: node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.21, node-tar's filesFilter in src/list.ts uses the recursive mapHas helper to walk an…

PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.38%
31.1th percentile
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.21, node-tar's filesFilter in src/list.ts uses the recursive mapHas helper to walk an archive entry path upward with path.dirname() and no segment cap when tar.t(...) or tar.x(...) receives a non-empty member-selection list. A crafted GNU L or PAX x long-path header with thousands of slash-separated segments reaches this.filter(entry.path, entry) in Parser[CONSUMEHEADER] in src/parse.ts before Unpack[CHECKPATH] applies maxDepth, causing an uncatchable RangeError stack overflow that terminates asynchronous and streaming Node.js consumers. This issue is fixed in version 7.5.21.

Affected

65 ranges· showing 25
VendorProductVersion rangeFixed in
3scale-amp2system-rhel8
3scale-amp2toolbox-rhel9
ansible-automation-platformautomation-portal
ansible-automation-platformbootc-automation-portal-rhel9
devspacescode-rhel9
devspacesdashboard-rhel9
devspacesopenvsx-rhel9
devspacespluginregistry-rhel9
devspacesudi-rhel9
exploit-intelligence-tech-previewvulnerability-analysis-rhel9
external-secrets-managementconsole-plugin-rhel9
gnutar
grafanagrafana
isaacsnode-tar< 7.5.217.5.21
mtamta-cli-rhel9
mtamta-generic-external-provider-rhel9
ocs4rhceph-rhel8
odf4mcg-core-rhel9
odf4ocs-client-console-rhel9
odf4odf-console-rhel9
odf4odf-multicluster-console-rhel9
openshift-pipelinespipelines-console-plugin-pf5-rhel9
openshift-pipelinespipelines-console-plugin-rhel8
openshift-pipelinespipelines-console-plugin-rhel9
openshift-service-meshkiali-ossmc-rhel9

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.