CVE-2026-59873: Isaacs Tar
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19.
Affected products
- Isaacs Tar: before 7.5.19 (fixed in 7.5.19)
Published 2026-07-08. Last modified 2026-07-10.