UBUNTU-CVE-2026-59873
node-tar versions prior to 7.5.19 do not enforce limits on decompressed data size, entry counts, or decompression ratio during archive extraction. This allows a crafted gzip bomb to exhaust disk space and CPU resources. The issue is fixed in version 7.5.19. Several specific Ubuntu package versions are affected.
AI Analysis
Technical Summary
The vulnerability in node-tar affects versions before 7.5.19 by lacking enforcement of hard upper bounds on total decompressed data, entry counts, and decompression ratio in extraction and parsing code paths. This flaw enables an attacker to craft a gzip bomb that can cause resource exhaustion on disk and CPU during archive extraction. The vulnerability is resolved in node-tar version 7.5.19. The affected Ubuntu package versions include =0.1.18-1, =1.0.3-2, =2.2.1-1, =4.4.10+ds1-2, =4.4.10+ds1-2ubuntu1, and =4.4.10+ds1-2ubuntu1+esm1.
Potential Impact
An attacker can supply a maliciously crafted gzip archive that, when extracted using vulnerable node-tar versions, can exhaust disk space and CPU resources on the target system. This can lead to denial of service conditions due to resource exhaustion. There is no indication of code execution or data corruption beyond resource exhaustion.
Mitigation Recommendations
Upgrade node-tar to version 7.5.19 or later where this issue is fixed. The affected Ubuntu package versions should be updated to versions that include this fix. Patch status is confirmed fixed in 7.5.19. No other mitigation is indicated.
UBUNTU-CVE-2026-59873
Description
node-tar versions prior to 7.5.19 do not enforce limits on decompressed data size, entry counts, or decompression ratio during archive extraction. This allows a crafted gzip bomb to exhaust disk space and CPU resources. The issue is fixed in version 7.5.19. Several specific Ubuntu package versions are affected.
CVSS v4.0
Affected software
pkg:deb/ubuntu/[email protected]~esm1?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/[email protected]~esm1?arch=source&distro=esm-apps/xenialpkg:deb/ubuntu/[email protected]+ds1-2ubuntu1+esm1?arch=source&distro=esm-apps/focalpkg:deb/ubuntu/[email protected]+ds1+~cs6.0.6-1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]+~cs7.0.5-3?arch=source&distro=noblepkg:deb/ubuntu/[email protected]+~cs7.0.8-1?arch=source&distro=questingpkg:deb/ubuntu/[email protected]+ds1+~cs6.1.13-10?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in node-tar affects versions before 7.5.19 by lacking enforcement of hard upper bounds on total decompressed data, entry counts, and decompression ratio in extraction and parsing code paths. This flaw enables an attacker to craft a gzip bomb that can cause resource exhaustion on disk and CPU during archive extraction. The vulnerability is resolved in node-tar version 7.5.19. The affected Ubuntu package versions include =0.1.18-1, =1.0.3-2, =2.2.1-1, =4.4.10+ds1-2, =4.4.10+ds1-2ubuntu1, and =4.4.10+ds1-2ubuntu1+esm1.
Potential Impact
An attacker can supply a maliciously crafted gzip archive that, when extracted using vulnerable node-tar versions, can exhaust disk space and CPU resources on the target system. This can lead to denial of service conditions due to resource exhaustion. There is no indication of code execution or data corruption beyond resource exhaustion.
Mitigation Recommendations
Upgrade node-tar to version 7.5.19 or later where this issue is fixed. The affected Ubuntu package versions should be updated to versions that include this fix. Patch status is confirmed fixed in 7.5.19. No other mitigation is indicated.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-59873
- Osv Schema Version
- 1.7.0
- Aliases
- []
- Ecosystems
- ["Ubuntu:Pro:14.04:LTS","Ubuntu:Pro:16.04:LTS","Ubuntu:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:25.10","Ubuntu:26.04:LTS"]
- Database Specific Severity
- null
- Cvss Version
- 4.0
Threat ID: 6a58b45468715ace43d6b9bc
Added to database: 07/16/2026, 10:37:08 UTC
Last enriched: 07/16/2026, 11:32:26 UTC
Last updated: 07/31/2026, 19:24:47 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.