Junglewise Threat Intelligence

CVE-2026-73566: npm tar stack overflow in mapHas filter with long paths

CVE-2026-73566 · Severity: low · CVSS 3.1 · Published 2026-07-24

Vendors: npm.

Executive brief

npm tar is a utility for reading and writing tar archives, commonly used for extracting package dependencies and processing uploaded files. A crafted tar file with an extremely long file path can trigger an uncontrollable recursive function that crashes the Node.js process, causing denial of service to any application that extracts or lists files with member selection filters applied.

Technical details

The vulnerability is an uncontrolled recursion stack-exhaustion flaw in the mapHas helper function used by filesFilter (src/list.ts). When tar.t() or tar.x() is called with a non-empty member-selection list, a filter is installed that recursively walks file paths using path.dirname() with no segment limit. An attacker can craft a tar archive containing a GNU-L or PAX-x long-path header with tens of thousands of "/" segments (up to 1 MiB). The filter invocation occurs inside Parser[CONSUMEHEADER] at src/parse.ts:253, outside the only try/catch block, causing an uncatchable RangeError that terminates the process. A ~188-byte gzip-compressed archive (≈26 KB uncompressed) is sufficient to trigger the crash on both async and streaming consumers.

Affected products

  • npm tar <=7.5.20

Timeline

  • 2026-07-24: disclosed
  • 2026-07-21: patched: Fixed in version 7.5.21

References