Known vulnerabilities in tar

Vendor: npm Inc.
Software: tar
Software CPE: cpe:2.3:a:npm:tar:*:*:*:*:*:nodejs:*:*
Total vulnerabilities: 8
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.8

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting tar tar is affected by 8 known vulnerabilities: 8 medium Critical High Medium Low

Vulnerabilities (8)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU139375 - Uncontrolled Recursion
CVE-2026-73566
CWE-674 Medium
No
No
7.5.21 26.07.2026 SB2026072605
#VU122099 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-24842
CWE-22 Medium
Available
No
7.5.7 28.01.2026 SB2026012845
SB20260202129
SB2026020564
and 8 more
#VU87734 - Resource exhaustion
CVE-2024-28863
CWE-400 Medium
No
No
6.2.1 22.03.2024 SB2024032234
SB2024052306
SB2024061114
and 30 more
#VU58206 - Absolute Path Traversal
CVE-2021-32803
CWE-36 Medium
No
No
3.2.3, 4.4.15, 5.0.7, 6.1.2 17.11.2021 SB2021080329
SB2022031104
SB2022060618
and 26 more
#VU58205 - Absolute Path Traversal
CVE-2021-32804
CWE-36 Medium
No
No
3.2.2, 4.4.14, 5.0.6, 6.1.1 17.11.2021 SB2021080328
SB2022031104
SB2022060618
and 27 more
#VU58204 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-37713
CWE-22 Medium
No
No
4.4.18, 5.0.10, 6.1.9 17.11.2021 SB2021111707
SB2022031104
SB2022060618
and 13 more
#VU58203 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-37712
CWE-22 Medium
No
No
4.4.18, 5.0.10, 6.1.9 17.11.2021 SB2021111707
SB2021111710
SB2022031104
and 24 more
#VU58202 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-37701
CWE-22 Medium
No
No
4.4.16, 5.0.8, 6.1.7 17.11.2021 SB2021111706
SB2021111710
SB2022031104
and 24 more