Sploitus

CVE-2026-59874

No indexed exploits for CVE-2026-59874 yet

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed in version 7.5.18.

Affected products
Confluence, Rocky Linux, Node-Tar
Isaacs Tar
< 7.5.18
Fix
Available
CVSS 4.0
8.7 HIGH
CVSS 3.1
7.5 HIGH
EPSS
0.4% (34th percentile)
Weakness
CWE-835
NVD status
Analyzed
Published
2026-07-08
CVE-2026-59874 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-59874 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-59874 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.