npm vulnerability intelligence

tar NPM Package
Vulnerability Check

tar for node

Critical BlueOak-1.0.0 v7.5.22
Vulnerability Analysis OSV Live

tar

v7.5.22 · BlueOak-1.0.0

Advisory Breakdown

Critical 1
High 14
Moderate 6
Low 0

Severity Rating

Critical

21 advisories

Critical

Weekly downloads

Total advisories

21

Latest version

7.5.22

License

BlueOak-1.0.0

Known advisories

OSV records for the npm ecosystem

21
GHSA-23hp-3jrh-7fpw CVE-2026-59873 critical

node-tar: Decompression/parse DoS via unlimited input

Affected: >=0 <7.5.19 Fixed in: 7.5.19 Updated Jul 21, 2026
View source
GHSA-29xp-372q-xqph CVE-2025-64118 moderate

node-tar has a race condition leading to uninitialized memory exposure

Affected: >=7.5.1 <7.5.2 Fixed in: 7.5.2 Updated Feb 4, 2026
View source
GHSA-34x7-hfp2-rc4v CVE-2026-24842 high

node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal

Affected: >=0 <7.5.7 Fixed in: 7.5.7 Updated Feb 4, 2026
View source
GHSA-3jfq-g458-7qm9 CVE-2021-32804 high

Arbitrary File Creation/Overwrite due to insufficient absolute path sanitization

Affected: >=0 <3.2.2, >=4.0.0 <4.4.14, >=5.0.0 <5.0.6, >=6.0.0 <6.1.1 Fixed in: 3.2.2, 4.4.14, 5.0.6, 6.1.1 Updated Jul 8, 2026
View source
GHSA-5955-9wpr-37jh CVE-2021-37713 high

Arbitrary File Creation/Overwrite on Windows via insufficient relative path sanitization

Affected: >=0 <4.4.18, >=5.0.0 <5.0.10, >=6.0.0 <6.1.9 Fixed in: 4.4.18, 5.0.10, 6.1.9 Updated Jul 8, 2026
View source
GHSA-83g3-92jg-28cx CVE-2026-26960 high

Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in node-tar Extraction

Affected: >=0 <7.5.8 Fixed in: 7.5.8 Updated Feb 20, 2026
View source
GHSA-8qq5-rm4j-mr97 CVE-2026-23745 high

node-tar is Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization

Affected: >=0 <7.5.3 Fixed in: 7.5.3 Updated Feb 22, 2026
View source
GHSA-8x88-c5mf-7j5w CVE-2026-59874 high

node-tar: Negative tar entry size causes infinite loop in archive replace

Affected: >=0 <7.5.18 Fixed in: 7.5.18 Updated Jul 21, 2026
View source
GHSA-9ppj-qmqm-q256 CVE-2026-31802 high

node-tar Symlink Path Traversal via Drive-Relative Linkpath

Affected: >=0 <7.5.11 Fixed in: 7.5.11 Updated Mar 13, 2026
View source
GHSA-9r2w-394v-53qc CVE-2021-37701 high

Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links

Affected: >=3.0.0 <4.4.16, >=5.0.0 <5.0.8, >=6.0.0 <6.1.7 Fixed in: 4.4.16, 5.0.8, 6.1.7 Updated Jul 8, 2026
View source
GHSA-f5x3-32g6-xq36 CVE-2024-28863 moderate

Denial of service while parsing a tar file due to lack of folders count validation

Affected: >=0 <6.2.1 Fixed in: 6.2.1 Updated Feb 4, 2026
View source
GHSA-gfjr-3jmm-4g9v CVE-2015-8860 high

Symlink Arbitrary File Overwrite in tar

Affected: >=0 <2.0.0 Fixed in: 2.0.0 Updated Nov 8, 2023
View source
GHSA-gvwx-54wh-qm9j CVE-2026-59875 moderate

node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records

Affected: >=0 <7.5.17 Fixed in: 7.5.17 Updated Jul 21, 2026
View source
GHSA-j44m-qm6p-hp7m CVE-2018-20834 high

Arbitrary File Overwrite in tar

Affected: >=3.0.0 <4.4.2, >=0 <2.2.2 Fixed in: 4.4.2, 2.2.2 Updated Nov 29, 2023
View source
GHSA-qffp-2rhf-9h96 CVE-2026-29786 high

tar has Hardlink Path Traversal via Drive-Relative Linkpath

Affected: >=0 <7.5.10 Fixed in: 7.5.10 Updated Mar 10, 2026
View source
GHSA-qq89-hq3f-393p CVE-2021-37712 high

Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links

Affected: >=3.0.0 <4.4.18, >=5.0.0 <5.0.10, >=6.0.0 <6.1.9 Fixed in: 4.4.18, 5.0.10, 6.1.9 Updated Jul 8, 2026
View source
GHSA-r292-9mhp-454m moderate

node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection

Affected: >=0 <7.5.21 Fixed in: 7.5.21 Updated Jul 25, 2026
View source
GHSA-r628-mhmh-qjhw CVE-2021-32803 high

Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning

Affected: >=3.0.0 <3.2.3, >=4.0.0 <4.4.15, >=5.0.0 <5.0.7, >=6.0.0 <6.1.2 Fixed in: 3.2.3, 4.4.15, 5.0.7, 6.1.2 Updated Jul 8, 2026
View source
GHSA-r6q2-hw4h-h46w CVE-2026-23950 high

Race Condition in node-tar Path Reservations via Unicode Ligature Collisions on macOS APFS

Affected: >=0 <7.5.4 Fixed in: 7.5.4 Updated Mar 16, 2026
View source
GHSA-vmf3-w455-68vh CVE-2026-53655 moderate

node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)

Affected: >=0 <7.5.16 Fixed in: 7.5.16 Updated Jun 18, 2026
View source
GHSA-w8wr-v893-vjvp CVE-2026-59871 moderate

node-tar: Process crash via PAX numeric path type confusion

Affected: >=0 <7.5.18 Fixed in: 7.5.18 Updated Jul 21, 2026
View source

Checked Aug 12, 2026, 7:44 PM from npm and OSV.dev

Package metadata

From the npm registry

Package name
tar
Ecosystem
npm
Latest version
7.5.22
License
BlueOak-1.0.0
Weekly downloads
Unavailable

Remediation boundary

What RequestGuard does — and doesn't — cover

RequestGuard does not fix npm package vulnerabilities. Dependency remediation happens through package updates, patches, lockfile changes, and maintainer guidance. RequestGuard can help mitigate runtime abuse around exposed web and API flows while remediation is handled separately.

Signup flows
Login attempts
API traffic

Data from npm registry and OSV.dev · Checked 8/12/2026, 7:44:51 PM