« Volver al listado

Isaacs

Isaacs TAR: vulnerabilidades y CVE

Isaacs TAR tiene 12 vulnerabilidades publicadas, 10 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE12
Últimos 12 meses10
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-59874Alta (8.7)0.64%—8 jul 2026
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress…
CVE-2026-59873Crítica (9.2)0.64%—8 jul 2026
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths…
CVE-2026-59871Alta (7.5)0.64%—8 jul 2026
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and linkpath values in src/pax.ts to JavaScript numbers, causing downstream path handling such as…
CVE-2026-53655Media (6.9)0.16%—22 jun 2026
node-tar is a full-featured Tar for Node.js. Prior to 7.5.16, tar (node-tar) applies a PAX extended header's size= record (and other PAX overrides) to the next header entry of any type, including intermediary metadata…
CVE-2026-31802Alta (8.2)0.18%—10 mar 2026
node-tar is a full-featured Tar for Node.js. Prior to version 7.5.11, tar (npm) can be tricked into creating a symlink that points outside the extraction directory by using a drive-relative symlink target such as…
CVE-2026-29786Alta (8.2)0.39%—7 mar 2026
node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction directory by using a drive-relative link target such as…
CVE-2026-26960Alta (7.1)0.20%—20 feb 2026
node-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-controlled archive can create a hardlink inside the extraction directory that points to a file outside the…
CVE-2026-24842Alta (8.2)0.62%—28 ene 2026
node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This…
CVE-2026-23950Media (5.9)0.26%—20 ene 2026
node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path-reservations` system. On…
CVE-2026-23745Alta (8.2)0.38%—16 ene 2026
node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries when preservePaths is false (the default secure behavior). This allows malicious…
CVE-2024-28863Media (6.5)0.93%—21 mar 2024
node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no limit on the number of sub-folders created in the folder creation process. An attacker who generates a large number of sub-folders can consume memory…
CVE-2018-20834Alta (7.5)3.1%—30 abr 2019
A vulnerability was found in node-tar before version 4.4.2 (excluding version 2.2.2). An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system,…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1203 Exploitation for Client Execution4
  2. T1190 Exploit Public-Facing Application3
  3. T1499.004 Application or System Exploitation3
  4. T1005 Data from Local System2
  5. T1565.001 Stored Data Manipulation2
  6. T1068 Exploitation for Privilege Escalation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Isaacs