CVE-2026-59874: Isaacs Tar
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed in version 7.5.18.
Affected products
- Isaacs Tar: before 7.5.18 (fixed in 7.5.18)
Published 2026-07-08. Last modified 2026-07-10.