Security vulnerabilities and automated fixes for cve 2026 73566 issues
1 post found
CVE-2026-73566 is a high-severity Denial of Service vulnerability in node-tar versions before 7.5.21, where specially crafted archives with extremely long path names can cause infinite loops during extraction. The fix upgrades the tar dependency from 7.5.19 to 7.5.21, which adds proper bounds checking and prevents CPU exhaustion attacks.