{"id":"CVE-2024-28863","aliases":["GHSA-f5x3-32g6-xq36"],"url":"https://o3.security/vulnerability/CVE-2024-28863","summary":"node-tar vulnerable to denial of service while parsing a tar file due to lack of folders count validation","details":"node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no limit on the number of sub-folders created in the folder creation process. An attacker who generates a large number of sub-folders can consume memory on the system running node-tar and even crash the Node.js client within few seconds of running it using a path with too many sub-folders inside. Version 6.2.1 fixes this issue by preventing extraction in excessively deep sub-folders.","published":"2024-03-21T22:10:23.603Z","modified":"2026-08-08T03:30:47.085972453Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"node-tar","fixedVersion":"6.2.1"},{"ecosystem":"npm","name":"tar","fixedVersion":"6.2.1"}],"fix":{"url":"https://github.com/isaacs/node-tar/commit/fe8cd57da5686f8695415414bda49206a545f7f7","label":"isaacs/node-tar@fe8cd57"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/28xxx/CVE-2024-28863.json"},{"type":"ADVISORY","url":"https://github.com/isaacs/node-tar/security/advisories/GHSA-f5x3-32g6-xq36"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-28863"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20240524-0005/"},{"type":"FIX","url":"https://github.com/isaacs/node-tar/commit/fe8cd57da5686f8695415414bda49206a545f7f7"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T03:30:47.085972453Z"}}