{"api_version":"v1","generated_at":"2026-10-07T13:35:00+00:00","product":{"cve_count":14,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-isaacs-node-tar-888171bda4c8","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/node-tar","name":"node-tar","next_cursor":null,"observations":[{"affected":"node-tar: < 7.5.21","affected_versions_present":true,"cve_id":"CVE-2026-73566","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73566","fixed":"7.5.21.","last_modified":"2026-08-21T19:08:31.345Z","patch_url":"https://github.com/isaacs/node-tar/security/advisories/GHSA-r292-9mhp-454m","primary_source":"","published":"2026-08-13T17:39:05.796Z"},{"affected":"< 7.5.18","affected_versions_present":true,"cve_id":"CVE-2026-59871","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-59871","fixed":"7.5.18.","last_modified":"2026-07-08T16:13:05.563Z","patch_url":"https://github.com/isaacs/node-tar/commit/e02a4e9e013c4be95302e2eb2047a942b883c27b","primary_source":"","published":"2026-07-08T15:25:09.519Z"},{"affected":"< 7.5.18","affected_versions_present":true,"cve_id":"CVE-2026-59874","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-59874","fixed":"7.5.18.","last_modified":"2026-07-08T17:00:42.937Z","patch_url":"https://github.com/isaacs/node-tar/commit/9e78bf058b2c22dd4d52e00d8922d5c06fc2f7b5","primary_source":"","published":"2026-07-08T15:23:47.527Z"},{"affected":"< 7.5.19","affected_versions_present":true,"cve_id":"CVE-2026-59873","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-59873","fixed":"7.5.19.","last_modified":"2026-07-08T19:41:26.372Z","patch_url":"https://github.com/isaacs/node-tar/commit/2812e9338665659b183aa7226518c307044957d3","primary_source":"","published":"2026-07-08T15:22:40.077Z"},{"affected":"< 7.5.17","affected_versions_present":true,"cve_id":"CVE-2026-59875","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-59875","fixed":"7.5.17.","last_modified":"2026-07-09T13:45:44.160Z","patch_url":"https://github.com/isaacs/node-tar/security/advisories/GHSA-gvwx-54wh-qm9j","primary_source":"","published":"2026-07-08T15:20:29.997Z"},{"affected":"< 7.5.16","affected_versions_present":true,"cve_id":"CVE-2026-53655","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-53655","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-23T16:09:06.835Z","patch_url":"https://github.com/isaacs/node-tar/security/advisories/GHSA-vmf3-w455-68vh","primary_source":"","published":"2026-06-22T14:55:50.133Z"},{"affected":"< 7.5.11","affected_versions_present":true,"cve_id":"CVE-2026-31802","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-31802","fixed":"Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258","last_modified":"2026-03-10T14:56:35.229Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-31802","primary_source":"","published":"2026-03-09T21:11:56.668Z"},{"affected":"node-tar: < 7.5.10","affected_versions_present":true,"cve_id":"CVE-2026-29786","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-29786","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-09-01T12:05:00.341Z","patch_url":"https://github.com/isaacs/node-tar/commit/7bc755dd85e623c0279e08eb3784909e6d7e4b9f","primary_source":"","published":"2026-03-07T15:32:22.748Z"},{"affected":"< 7.5.8","affected_versions_present":true,"cve_id":"CVE-2026-26960","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-26960","fixed":"7.5.8.","last_modified":"2026-02-20T15:35:27.586Z","patch_url":"https://github.com/isaacs/node-tar/commit/2cb1120bcefe28d7ecc719b41441ade59c52e384","primary_source":"","published":"2026-02-20T01:07:52.979Z"},{"affected":"node-tar: < 7.5.7","affected_versions_present":true,"cve_id":"CVE-2026-24842","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-24842","fixed":"RHSA-2026:33371: Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server","last_modified":"2026-09-07T12:05:07.837Z","patch_url":"https://github.com/isaacs/node-tar/commit/f4a7aa9bc3d717c987fdf1480ff7a64e87ffdb46","primary_source":"","published":"2026-01-28T00:20:13.261Z"},{"affected":"node-tar: < 7.5.4","affected_versions_present":true,"cve_id":"CVE-2026-23950","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-23950","fixed":"RHSA-2026:18480: Red Hat Enterprise Linux AppStream (v. 10)","last_modified":"2026-09-01T12:04:49.226Z","patch_url":"https://github.com/isaacs/node-tar/commit/3b1abfae650056edfabcbe0a0df5954d390521e6","primary_source":"","published":"2026-01-20T00:40:48.510Z"},{"affected":"node-tar: < 7.5.3","affected_versions_present":true,"cve_id":"CVE-2026-23745","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-23745","fixed":"RHSA-2026:18480: Red Hat Enterprise Linux AppStream (v. 10)","last_modified":"2026-09-07T12:04:48.619Z","patch_url":"https://github.com/isaacs/node-tar/security/advisories/GHSA-8qq5-rm4j-mr97","primary_source":"","published":"2026-01-16T22:00:08.769Z"},{"affected":"= 7.5.1","affected_versions_present":true,"cve_id":"CVE-2025-64118","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-64118","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-10-30T18:42:19.663Z","patch_url":"","primary_source":"","published":"2025-10-30T17:50:20.421Z"},{"affected":"< 6.2.1","affected_versions_present":true,"cve_id":"CVE-2024-28863","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-28863","fixed":"Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258","last_modified":"2025-02-13T17:47:34.618Z","patch_url":"https://access.redhat.com/security/cve/CVE-2024-28863","primary_source":"","published":"2024-03-21T22:10:23.603Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"isaacs"}}
