{"id":"CVE-2026-59871","title":"node-tar: node-tar: Denial of Service due to incorrect PAX path handling (CVE-2026-59871)","summary":"A flaw was found in node-tar, a library for manipulating tar archives in Node.js. This vulnerability occurs when the library incorrectly converts specific archive path values into numbers, leading to an error during subsequent path process…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","cvssSource":"vendor","cwe":["CWE-843","CWE-704"],"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","affected":["confidential_compute_attestation","cryostat 4","exploit_intelligence","migration_toolkit_for_containers","node_healthcheck_operator","openshift_pipelines","openshift_service_mesh 3","3scale_api_management_platform 2","advanced_cluster_management_for_kubernetes 2","amq_broker 7","build_of_apache_camel_hawtio 4","build_of_apache_camel_for_spring_boot 4","build_of_podman_desktop","connectivity_link 1","developer_hub","enterprise_linux 10","enterprise_linux 6","enterprise_linux 7","enterprise_linux 8","enterprise_linux 9","enterprise_linux_ai_rhel_ai 3","jboss_enterprise_application_platform 7","jboss_enterprise_application_platform_expansion_pack","openshift_ai_rhoai","openshift_container_platform 4","openshift_data_foundation 4","openshift_dev_spaces","satellite 6","single_sign_on 7","trusted_artifact_signer","self_service_automation_portal 2"],"patched":["tar 7.5.18"],"published":"2026-07-08","updated":"2026-09-10","sourceUpdated":"2026-09-10T15:09:00+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59871.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59871.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-59871"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2498126"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-59871"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59871"},{"url":"https://github.com/isaacs/node-tar/commit/e02a4e9e013c4be95302e2eb2047a942b883c27b"},{"url":"https://github.com/isaacs/node-tar/releases/tag/v7.5.18"},{"url":"https://github.com/isaacs/node-tar/security/advisories/GHSA-w8wr-v893-vjvp"},{"url":"https://github.com/advisories/GHSA-w8wr-v893-vjvp"}],"tags":["csaf","vex","red-hat","ghsa","npm"],"epss":0.00644,"epssPercentile":0.49103,"aliases":["GHSA-w8wr-v893-vjvp"],"ecosystem":"npm","ingestedAt":"2026-07-20T22:43:35.311Z","slug":"CVE-2026-59871","body":"## Overview\n\nA flaw was found in node-tar, a library for manipulating tar archives in Node.js. This vulnerability occurs when the library incorrectly converts specific archive path values into numbers, leading to an error during subsequent path processing. An attacker could exploit this to cause the application using node-tar to crash, resulting in a denial of service.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Confidential Compute Attestation, Cryostat 4, Exploit Intelligence, Migration Toolkit for Containers, Node HealthCheck Operator, OpenShift Pipelines, … · no fix planned: Confidential Compute Attestation, Cryostat 4, Exploit Intelligence, Migration Toolkit for Containers, … · updated 2026-09-10 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59871.json)\n\n**node-tar: node-tar: Denial of Service due to incorrect PAX path handling** — rated Moderate by Red Hat. Released 2026-07-08, updated 2026-09-10.\n\nAffected:\n\n- Confidential Compute Attestation\n- Cryostat 4\n- Exploit Intelligence\n- Migration Toolkit for Containers\n- Node HealthCheck Operator\n- OpenShift Pipelines\n- OpenShift Service Mesh 3\n- Red Hat 3scale API Management Platform 2\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat AMQ Broker 7\n- Red Hat build of Apache Camel - HawtIO 4\n- Red Hat build of Apache Camel for Spring Boot 4\n- Red Hat Build of Podman Desktop\n- Red Hat Connectivity Link 1\n- Red Hat Developer Hub\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat JBoss Enterprise Application Platform 7\n- Red Hat JBoss Enterprise Application Platform Expansion Pack\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenShift Container Platform 4\n- Red Hat Openshift Data Foundation 4\n- Red Hat OpenShift Dev Spaces\n- Red Hat Satellite 6\n- Red Hat Single Sign-On 7\n- Red Hat Trusted Artifact Signer\n- Self-service automation portal 2\n\nNo fix planned:\n\n- Confidential Compute Attestation\n- Cryostat 4\n- Exploit Intelligence\n- Migration Toolkit for Containers\n- Node HealthCheck Operator\n- OpenShift Pipelines\n- OpenShift Service Mesh 3\n- Red Hat 3scale API Management Platform 2\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat AMQ Broker 7\n- Red Hat build of Apache Camel - HawtIO 4\n- Red Hat build of Apache Camel for Spring Boot 4\n- Red Hat Build of Podman Desktop\n- Red Hat Connectivity Link 1\n- Red Hat Developer Hub\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat JBoss Enterprise Application Platform 7\n- Red Hat JBoss Enterprise Application Platform Expansion Pack\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenShift Container Platform 4\n- Red Hat Openshift Data Foundation 4\n- Red Hat OpenShift Dev Spaces\n- Red Hat Satellite 6\n- Red Hat Single Sign-On 7\n- Red Hat Trusted Artifact Signer\n- Self-service automation portal 2\n\nNot affected:\n\n- Red Hat Hardened Images\n\n## Remediation\n\nFix deferred\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.\n\n## Package advisory (CVE-2026-59871)\n\nAffected packages:\n\n- `tar <= 7.5.17`\n\nPatched in:\n\n- `tar 7.5.18`\n\nSource: https://github.com/advisories/GHSA-w8wr-v893-vjvp","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}