Executive brief
A vulnerability in the node-tar library, used for handling compressed archive files, can allow an attacker to crash or freeze an application. By providing a specially crafted archive file with a negative size value, an attacker can force the software into an infinite loop. This results in a denial-of-service (DoS) condition where the system becomes unresponsive and cannot process other tasks.
Technical details
The vulnerability is an infinite loop (CWE-835) within the `tar.replace()` API of node-tar. When scanning an existing archive to append new entries, the library parses tar headers and advances the file position based on the entry size. An attacker can craft a header using base-256 encoding to specify a negative entry size (e.g., -512). When the library adds the standard 512-byte header offset to this negative size, the net progress is zero, causing the scanner to repeatedly parse the same header. This can be exploited if an application performs replacement operations on attacker-controlled archives. The issue is fixed in version 7.5.18.
Affected products
- isaacs/node-tar tar <= 7.5.17
Timeline
- 2026-06-27: patched: Fix released in version 7.5.18
- 2026-07-08: advisory: NVD published CVE-2026-59874
- 2026-07-20: disclosed: GitHub Advisory GHSA-8x88-c5mf-7j5w published