Vendorsisaacstarall versions
Vulnerabilities

isaacs tar

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2026-59873
node-tar: Decompression/parse DoS via unlimited input
Published 2026-07-08 · Analyzed
9.2EPSS 0.006
CVE-2026-23950
node-tar has Race Condition in Path Reservations via Unicode Ligature Collisions on macOS APFS
Published 2026-01-20 · Modified
8.8EPSS 0.003
CVE-2026-59874
node-tar: Negative tar entry size causes infinite loop in archive replace
Published 2026-07-08 · Analyzed
8.7EPSS 0.006
CVE-2026-29786
node-tar: Hardlink Path Traversal via Drive-Relative Linkpath
Published 2026-03-07 · Modified
8.6EPSS 0.004
CVE-2026-24842
node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal
Published 2026-01-28 · Modified
8.2EPSS 0.006
CVE-2026-23745
node-tar Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization
Published 2026-01-16 · Modified
8.2EPSS 0.004
CVE-2026-31802
node-tar Symlink Path Traversal via Drive-Relative Linkpath
Published 2026-03-09 · Analyzed
8.2EPSS 0.002
CVE-2018-20834
A vulnerability was found in node-tar before version 4.4.2 (excluding version 2.2.2). An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same name as the hardlink. This plain file content replaces the existing file content. A patch has been applied to node-tar v2.2.2).
Published 2019-04-30 · Modified
7.5EPSS 0.031
CVE-2026-59871
node-tar: Process crash via PAX numeric path type confusion
Published 2026-07-08 · Analyzed
7.5EPSS 0.006
CVE-2026-26960
node-tar has Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in Extraction
Published 2026-02-20 · Analyzed
7.1EPSS 0.002
CVE-2026-53655
node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)
Published 2026-06-22 · Analyzed
6.9EPSS 0.002
CVE-2024-28863
node-tar vulnerable to denial of service while parsing a tar file due to lack of folders count validation
Published 2024-03-21 · Analyzed
6.5EPSS 0.009