CVE-2026-59875
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX path and linkpath re
CVSS
5.3
Medium
EPSS
0.3%
p21
KEV
—
Exploit Today
6
0-100
Published: Jul 8, 2026 · Last modified: Jul 10, 2026 · CWE-248
0.3%EPSS · 30 days0.3%
2026-07-092026-07-21
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX path and linkpath records in src/pax.ts, allowing a crafted archive with values to reach fs.lstat or fs.open and terminate the process with an uncaught exception. This issue is fixed in version 7.5.17.
- github.comhttps://github.com/isaacs/node-tar/commit/7a635c29f5edbf083557374d43984273ecfed5b3
- github.comhttps://github.com/isaacs/node-tar/releases/tag/v7.5.17
- github.comhttps://github.com/isaacs/node-tar/security/advisories/GHSA-gvwx-54wh-qm9j
- github.comhttps://github.com/isaacs/node-tar/security/advisories/GHSA-gvwx-54wh-qm9j
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-646127.5 HIG27.3%
——8A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installing an error recovery handler, causing the CUPS image filter process to abort when processing a malformed PNG file. An unauthenticated attacker could exploit this by submitting a specially crafted PNG print job, leading to denial of service of the in-flight print job.6hCVE-2026-637477.5 HIG28.2%
——8SurrealDB versions before 3.1.0 contain a denial of service vulnerability in the RPC use handler that panics when db is set without a namespace. Unauthenticated attackers can send a malformed WebSocket message to the /rpc endpoint to crash the server process.6hCVE-2025-71391—18.2%
——5SurrealDB versions before 2.2.2 contain an uncaught exception vulnerability in the net module that allows authenticated users to crash the database. Attackers can send crafted HTTP queries containing null bytes to the /sql endpoint, causing an unhandled exception that crashes the SurrealDB instance and any dependent applications.6hCVE-2024-583696.5 MED16.2%
——5SurrealDB versions before 1.1.1 fail to properly validate invocation of custom parameters and functions at root or namespace levels, causing server panic. Authorized clients can invoke these entities at unsupported levels to crash the SurrealDB server, resulting in denial of service.6hCVE-2024-583687.5 HIG30.0%
——9SurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST API requests containing special characters. Unauthenticated attackers can send crafted HTTP requests with malformed header values to trigger an uncaught exception that crashes the server.6hCVE-2024-583656.5 MED16.3%
——5SurrealDB versions before 1.2.0 contain an uncaught exception vulnerability in the query executor when processing calls to nonexistent built-in functions. Authorized clients can craft pre-parsed queries invoking nonexistent functions to trigger a panic that crashes the server.6h