Tar
Vendor:
First CVE: Apr 30, 2019 · Active for 7 years
12
Total CVEs
More Total CVEs than 90% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Tar over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 30, 2019
7 years ago
Most Recent CVE
Jul 8, 2026
16 days ago
CVE Severity & Scoring
Tar12 CVEs
50%
50%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local5 (41.7%)
Network7 (58.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (91.7%)
High1 (8.3%)
Unknown0 (0.0%)
User Interaction
None6 (50.0%)
Unknown0 (0.0%)
Required6 (50.0%)
Privileges Required
Low1 (8.3%)
High0 (0.0%)
None11 (91.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-59873HIGH node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression | Jul 8, 2026 | 7.5 | 37 | NO | NO |
CVE-2026-59874HIGH node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing th | Jul 8, 2026 | 7.5 | 35 | NO | NO |
CVE-2026-59871HIGH node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and linkpath values in src/pax.ts to JavaScript numbers, causing do | Jul 8, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-24842HIGH node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actu | Jan 28, 2026 | 8.2 | 30 | NO | NO |
CVE-2026-23745MEDIUM node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries when preservePaths is false (the default s | Jan 16, 2026 | 6.1 | 28 | NO | NO |
CVE-2026-53655MEDIUM node-tar is a full-featured Tar for Node.js. Prior to 7.5.16, tar (node-tar) applies a PAX extended header's size= record (and other PAX overrides) to the next header entry of any | Jun 22, 2026 | 5.5 | 27 | NO | NO |
CVE-2026-29786MEDIUM node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction directory by using a drive-rela | Mar 7, 2026 | 6.3 | 27 | NO | NO |
CVE-2026-26960HIGH node-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-controlled archive can create a hardlink inside the extraction dire | Feb 20, 2026 | 7.1 | 27 | NO | NO |
CVE-2026-23950MEDIUM node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path- | Jan 20, 2026 | 5.9 | 26 | NO | NO |
CVE-2018-20834HIGH A vulnerability was found in node-tar before version 4.4.2 (excluding version 2.2.2). An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a | Apr 30, 2019 | 7.5 | 26 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Tar
Top CWEs
Versions
No cataloged versions.