
🚨 2MB file 💥 2GB server crash CVE-2026-59873 affects node-tar ≤7.5.18. A crafted gzip bomb can max out CPU, fill disk space and crash services—no authentication required. Upgrade to 7.5.19+ immediately. FULL REPORT: https://www.ox.security/blog/cve-2026-59873-decompression-dos-via-unlimited-input-in-node-tar-90m-weekly-downloads-affected/ -- #CyberSecurity #NodeJS #CVE https://t.co/UwntaafsLF
Post summary
A DoS vulnerability in node-tar allows a crafted gzip bomb to exhaust CPU, fill disk space, and crash services; users are urged to immediately upgrade to 7.5.19+.




