Node.js Tar Archive Library Vulnerability Affecting Node-Tar Product
CVE-2026-73566

7.5HIGH

Key Information:

Vendor

Isaacs

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-73566?

A vulnerability in the node-tar library allows a specially crafted tar archive to trigger a stack overflow in Node.js consumers. This occurs due to improper handling of long-path headers, leading to an unmanageable number of entries in the file filter process. As a result, asynchronous and streaming applications using affected versions may terminate unexpectedly. This issue has been resolved in version 7.5.21.

Affected Version(s)

node-tar < 7.5.21

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.