Description
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed in version 7.5.18.
Severity (CVSS)
| Base score | 8.7 |
|---|---|
| Severity | High |
| Version | CVSS 4.0 |
| Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
| Provided by | CNA |
Weaknesses
- CWE-835 — CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop')
Affected products
| Vendor | Product | Versions |
|---|---|---|
| isaacs | node-tar | < 7.5.18 |
References
- https://github.com/isaacs/node-tar/security/advisories/GHSA-8x88-c5mf-7j5w (x_refsource_CONFIRM)
- https://github.com/isaacs/node-tar/commit/9e78bf058b2c22dd4d52e00d8922d5c06fc2f7b5 (x_refsource_MISC)
- https://github.com/isaacs/node-tar/releases/tag/v7.5.18 (x_refsource_MISC)
Generated from the official CVE List on 09 Jul 2026 07:08 UTC.