{"id":"CVE-2026-59875","aliases":["GHSA-gvwx-54wh-qm9j"],"url":"https://o3.security/vulnerability/CVE-2026-59875","summary":"node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records","details":"node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX path and linkpath records in src/pax.ts, allowing a crafted archive with values to reach fs.lstat or fs.open and terminate the process with an uncaught exception. This issue is fixed in version 7.5.17.","published":"2026-07-08T15:20:29.997Z","modified":"2026-08-12T03:51:30.680948805Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},"epss":{"score":0.00507,"percentile":0.41421,"asOf":"2026-09-06"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"tar","fixedVersion":"7.5.17"}],"fix":{"url":"https://github.com/isaacs/node-tar/commit/7a635c29f5edbf083557374d43984273ecfed5b3","label":"isaacs/node-tar@7a635c2"},"references":[{"type":"WEB","url":"https://github.com/isaacs/node-tar/releases/tag/v7.5.17"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59875.json"},{"type":"ADVISORY","url":"https://github.com/isaacs/node-tar/security/advisories/GHSA-gvwx-54wh-qm9j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59875"},{"type":"FIX","url":"https://github.com/isaacs/node-tar/commit/7a635c29f5edbf083557374d43984273ecfed5b3"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:30.680948805Z"}}