Isaacs
Isaacs TAR: vulnerabilidades y CVE
Isaacs TAR tiene 12 vulnerabilidades publicadas, 10 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE12
Últimos 12 meses10
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-59874 | Alta (8.7) | 0.64% | — | 8 jul 2026 | node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress… |
| CVE-2026-59873 | Crítica (9.2) | 0.64% | — | 8 jul 2026 | node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths… |
| CVE-2026-59871 | Alta (7.5) | 0.64% | — | 8 jul 2026 | node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and linkpath values in src/pax.ts to JavaScript numbers, causing downstream path handling such as… |
| CVE-2026-53655 | Media (6.9) | 0.16% | — | 22 jun 2026 | node-tar is a full-featured Tar for Node.js. Prior to 7.5.16, tar (node-tar) applies a PAX extended header's size= record (and other PAX overrides) to the next header entry of any type, including intermediary metadata… |
| CVE-2026-31802 | Alta (8.2) | 0.18% | — | 10 mar 2026 | node-tar is a full-featured Tar for Node.js. Prior to version 7.5.11, tar (npm) can be tricked into creating a symlink that points outside the extraction directory by using a drive-relative symlink target such as… |
| CVE-2026-29786 | Alta (8.2) | 0.39% | — | 7 mar 2026 | node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction directory by using a drive-relative link target such as… |
| CVE-2026-26960 | Alta (7.1) | 0.20% | — | 20 feb 2026 | node-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-controlled archive can create a hardlink inside the extraction directory that points to a file outside the… |
| CVE-2026-24842 | Alta (8.2) | 0.62% | — | 28 ene 2026 | node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This… |
| CVE-2026-23950 | Media (5.9) | 0.26% | — | 20 ene 2026 | node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path-reservations` system. On… |
| CVE-2026-23745 | Alta (8.2) | 0.38% | — | 16 ene 2026 | node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries when preservePaths is false (the default secure behavior). This allows malicious… |
| CVE-2024-28863 | Media (6.5) | 0.93% | — | 21 mar 2024 | node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no limit on the number of sub-folders created in the folder creation process. An attacker who generates a large number of sub-folders can consume memory… |
| CVE-2018-20834 | Alta (7.5) | 3.1% | — | 30 abr 2019 | A vulnerability was found in node-tar before version 4.4.2 (excluding version 2.2.2). An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system,… |