CVE-2026-59873Patch(isaacs / tar)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch isaacs tar systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tar

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 4 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-07-21); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
tar

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-07-11: 1Mentions · 2026-07-21: 2Mentions · 2026-08-08: 1Mentions · 2026-08-15: 1Patch / Workaround · 2026-07-11: 1Patch / Workaround · 2026-07-21: 2Patch / Workaround · 2026-08-15: 1Technical Details · 2026-07-11: 1Technical Details · 2026-07-21: 2Technical Details · 2026-08-08: 107-1107-2108-0808-15
Signal classification2 categories
Patch
480.0%
Disclosure
120.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-07-111
Patch1
2026-07-212
Patch2
2026-08-081
Disclosure1
2026-08-151
Patch1
Full discourse5 posts
  • OX Security@OX__Security
    Patch

    🚨 2MB file 💥 2GB server crash CVE-2026-59873 affects node-tar ≤7.5.18. A crafted gzip bomb can max out CPU, fill disk space and crash services—no authentication required. Upgrade to 7.5.19+ immediately. FULL REPORT: https://www.ox.security/blog/cve-2026-59873-decompression-dos-via-unlimited-input-in-node-tar-90m-weekly-downloads-affected/ -- #CyberSecurity #NodeJS #CVE https://t.co/UwntaafsLF

    Post summary

    A DoS vulnerability in node-tar allows a crafted gzip bomb to exhaust CPU, fill disk space, and crash services; users are urged to immediately upgrade to 7.5.19+.

    171821.8K
    400 followersView on X
  • Joshua Builds@joshuabuilds_
    Patch

    @OX__Security wrote an article about a CVE in Node-Tar that I found! (My name is credited in the article too) Check it out! (It was a really cool vuln to find) and thanks @izs for patching it! https://www.ox.security/blog/cve-2026-59873-decompression-dos-via-unlimited-input-in-node-tar-90m-weekly-downloads-affected/ #vulnerability #cve #node #tar

    Post summary

    The tweet links to a blog article on CVE‑2026‑59873 in Node‑Tar, acknowledges the issue, and thanks a developer for issuing a patch—no PoC or exploit details are provided.

    100921.1K
    1.3K followersView on X
  • Moshe Siman Tov Bustan@MosheTov
    Patch

    The fix for CVE-2026-59873 wraps the 'data' event listener to validate the compression to decompression ratio before consuming the data. It sounds like a small fix, something that should have been baked into the design, but was missed - and enabled a simple zip bomb attack to run on any node-tar version. Update your node-tar version to 7.5.19 or later if you use node-tar to decompress user generated zip files. Read the full analysis: https://www.ox.security/blog/cve-2026-59873-decompression-dos-via-unlimited-input-in-node-tar-90m-weekly-downloads-affected/

    Post summary

    The text announces a fix for CVE‑2026‑59873 by advising users to upgrade node‑tar to 7.5.19 or newer, highlighting the vulnerability’s zip bomb exploitation method.

    10010324
    1.1K followersView on X
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-59873: node-tar Decompression Denial of Service - What It Means for Your Business and How to Respond https://hubs.li/Q04skZHT0

    Post summary

    The snippet announces CVE‑2026‑59873, a node‑tar Decompression Denial of Service vulnerability, but provides only minimal technical detail and no evidence of exploitation, patch, or debunking.

    0000038
    32 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH SEVERITY: CVE-2026-59873 CVSS 7.5 - node-tar library for Node.js vulnerable to gzip bomb attacks causing disk/CPU exhaustion. Affects versions <7.5.19. Patch immediately to v7.5.19+ #CVE #Vulnerability #PatchNow https://t.co/gDw0lfsnFh

    Post summary

    The tweet highlights a high‑severity gzip bomb vulnerability (CVE-2026-59873) and urges users to patch to version 7.5.19+; no exploit or active attack details are provided.

    0000046
    71 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appisaacstar-node.js-

Explore more