21 Total advisories
21 Vulnerabilities
0 Malware

Dependency scanning

Check whether tar is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

MEDIUM 5.3
npm

CVE-2026-59871

node-tar: Process crash via PAX numeric path type confusion

HIGH 7.5
npm

CVE-2026-73566

node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection

HIGH 7.5
npm

CVE-2026-59874

node-tar: Negative tar entry size causes infinite loop in archive replace

HIGH 7.5
npm

CVE-2026-59873

node-tar: Decompression/parse DoS via unlimited input

UNKNOWN
npm

CVE-2026-53655

node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)

HIGH 8.8
npm

CVE-2026-23950

Race Condition in node-tar Path Reservations via Unicode Ligature Collisions on macOS APFS

UNKNOWN
npm

CVE-2026-23745

node-tar is Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization

MEDIUM 5.3
npm

CVE-2026-59875

node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records

UNKNOWN
npm

CVE-2026-29786

tar has Hardlink Path Traversal via Drive-Relative Linkpath

UNKNOWN
npm

CVE-2026-31802

node-tar Symlink Path Traversal via Drive-Relative Linkpath

HIGH 7.1
npm

CVE-2026-26960

Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in node-tar Extraction

HIGH 8.2
npm

CVE-2026-24842

node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal

UNKNOWN
npm

CVE-2025-64118

node-tar has a race condition leading to uninitialized memory exposure

MEDIUM 6.5
npm

CVE-2024-28863

Denial of service while parsing a tar file due to lack of folders count validation

HIGH 8.2
npm

CVE-2021-37701

Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links

HIGH 8.2
npm

CVE-2021-32804

Arbitrary File Creation/Overwrite due to insufficient absolute path sanitization

HIGH 8.2
npm

CVE-2021-37713

Arbitrary File Creation/Overwrite on Windows via insufficient relative path sanitization

HIGH 8.2
npm

CVE-2021-37712

Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links

HIGH 8.2
npm

CVE-2021-32803

Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning

HIGH 7.5
npm

CVE-2018-20834

Arbitrary File Overwrite in tar

HIGH 7.5
npm

CVE-2015-8860

Symlink Arbitrary File Overwrite in tar

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes