node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.21, node-tar's filesFilter in src/list.ts uses the recursive mapHas helper to walk an archive entry path upward with path.dirname() and no segment cap when tar.t(...) or tar.x(...) receives a non-empty member-selection list. A crafted GNU L or PAX x long-path header with thousands of slash-separated segments reaches this.filter(entry.path, entry) in Parser[CONSUMEHEADER] in src/parse.ts before Unpack[CHECKPATH] applies maxDepth, causing an uncatchable RangeError stack overflow that terminates asynchronous and streaming Node.js consumers. This issue is fixed in version 7.5.21.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-13 18:18
Updated : 2026-09-16 13:42
NVD link : CVE-2026-73566
Mitre link : CVE-2026-73566
CVE.ORG link : CVE-2026-73566
JSON object : View
Products Affected
No product.
