REDHAT-BUG-2498120: High severity node-tar vulnerability
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
node-tarto a version that resolves this vulnerability.Fixed in 7.5.19
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2498120?
The severity of REDHAT-BUG-2498120 is classified as high with a score of 7.
How do I fix REDHAT-BUG-2498120?
To fix REDHAT-BUG-2498120, upgrade to node-tar version 7.5.19 or later.
What does REDHAT-BUG-2498120 affect?
REDHAT-BUG-2498120 affects the node-tar library, which is used for tar archive manipulation in Node.js.
What is the potential impact of REDHAT-BUG-2498120?
The potential impact of REDHAT-BUG-2498120 includes the exhaustion of disk space due to unbounded decompressed data from crafted gzip bombs.
When was REDHAT-BUG-2498120 published?
REDHAT-BUG-2498120 was published on July 8, 2026.