CVE-2026-26960
- EPSS 0.01%
- Veröffentlicht 20.02.2026 01:07:52
- Zuletzt bearbeitet 20.02.2026 19:24:16
node-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-controlled archive can create a hardlink inside the extraction directory that points to a file outside the extraction root, enabling arbi...
CVE-2026-24842
- EPSS 0.01%
- Veröffentlicht 28.01.2026 00:20:13
- Zuletzt bearbeitet 02.02.2026 14:30:10
node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacker to craft ...
CVE-2026-23950
- EPSS 0.01%
- Veröffentlicht 20.01.2026 01:15:57
- Zuletzt bearbeitet 18.02.2026 15:50:29
node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path-reservations` system. On case-insensitive or normalization-insensitive...
CVE-2026-23745
- EPSS 0.01%
- Veröffentlicht 16.01.2026 22:16:26
- Zuletzt bearbeitet 18.02.2026 16:20:07
node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries when preservePaths is false (the default secure behavior). This allows malicious archives to bypass the extracti...
CVE-2024-28863
- EPSS 0.45%
- Veröffentlicht 21.03.2024 23:15:10
- Zuletzt bearbeitet 16.12.2025 17:25:07
node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no limit on the number of sub-folders created in the folder creation process. An attacker who generates a large number of sub-folders can consume memory on the system running node-tar...
CVE-2018-20834
- EPSS 0.75%
- Veröffentlicht 30.04.2019 19:29:03
- Zuletzt bearbeitet 04.02.2026 18:31:45
A vulnerability was found in node-tar before version 4.4.2 (excluding version 2.2.2). An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later pl...