Type conversion in node-tar - CVE-2026-59871
Published: June 29, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to incorrect type conversion or cast in the PAX header parser when parsing a crafted tar archive with an all-digit path value. A remote attacker can supply a specially crafted tar archive to cause a denial of service.
The crash occurs as an uncaught TypeError during extraction and bypasses application-level error handling, including error and warning handlers.
Affected software
Confluence Data Center
Jira Service Management Data Center
Jira Software Data Center
How to mitigate CVE-2026-59871
Confluence Data Center - addressed in versions 9.2.22, 10.2.14
Jira Service Management Data Center - addressed in versions 10.3.18, 11.3.10
Jira Software Data Center - addressed in versions 10.3.18, 11.3.9