Node.js Tar Archive Library Vulnerability Affecting Node-Tar Product
CVE-2026-73566
7.5HIGH
What is CVE-2026-73566?
A vulnerability in the node-tar library allows a specially crafted tar archive to trigger a stack overflow in Node.js consumers. This occurs due to improper handling of long-path headers, leading to an unmanageable number of entries in the file filter process. As a result, asynchronous and streaming applications using affected versions may terminate unexpectedly. This issue has been resolved in version 7.5.21.
Affected Version(s)
node-tar < 7.5.21
