CVE-2026-59875

EUVD-2026-42303
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX path and linkpath records in src/pax.ts, allowing a crafted archive with values to reach fs.lstat or fs.open and terminate the process with an uncaught exception. This issue is fixed in version 7.5.17.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 21.85%
Debian logo
Debian Releases
Debian Product
Codename
node-tar
bookworm
postponed
bookworm (security)
vulnerable
bullseye
postponed
bullseye (security)
vulnerable
forky
7.5.22+~4.0.1-1
fixed
sid
7.5.22+~4.0.1-1
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
node-tar
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage
trusty
needs-triage
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
nodejs24
Amazon Linux 2023
1:24.18.1-1.amzn2023.0.2
fixed
nodejs24-debuginfo
Amazon Linux 2023
1:24.18.1-1.amzn2023.0.2
fixed
nodejs24-debugsource
Amazon Linux 2023
1:24.18.1-1.amzn2023.0.2
fixed
nodejs24-devel
Amazon Linux 2023
1:24.18.1-1.amzn2023.0.2
fixed
nodejs24-docs
Amazon Linux 2023
1:24.18.1-1.amzn2023.0.2
fixed
nodejs24-full-i18n
Amazon Linux 2023
1:24.18.1-1.amzn2023.0.2
fixed
nodejs24-libs
Amazon Linux 2023
1:24.18.1-1.amzn2023.0.2
fixed
nodejs24-libs-debuginfo
Amazon Linux 2023
1:24.18.1-1.amzn2023.0.2
fixed
nodejs24-npm
Amazon Linux 2023
1:11.16.0-1.24.18.1.1.amzn2023.0.2
fixed
v8-13.6-devel
Amazon Linux 2023
3:13.6.233.17-1.24.18.1.1.amzn2023.0.2
fixed