CVE Details
| CVE ID |
Severity |
Affected Package |
Installed Version |
Fixed Version |
Date Published |
Date of Scan |
| CVE-2026-73566 |
HIGH |
tar |
7.5.16 |
7.5.21 |
2026-08-13T18:18:19.25Z |
2026-08-22T10:18:29.036623362Z |
Affected Docker Images
| Image Name |
SHA |
public.ecr.aws/lambda/nodejs:latest |
public.ecr.aws/lambda/nodejs@sha256:1ff82da6fcff5cb4d0518505aeba477acab4d5bc230e257ac3d0450a77fbc169 |
public.ecr.aws/lambda/nodejs:24 |
public.ecr.aws/lambda/nodejs@sha256:1ff82da6fcff5cb4d0518505aeba477acab4d5bc230e257ac3d0450a77fbc169 |
public.ecr.aws/lambda/nodejs:22 |
public.ecr.aws/lambda/nodejs@sha256:8e26dc1314af70609939e524f4474a3043a945bfe862779ef408deb2962ce945 |
Description
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.21, node-tar's filesFilter in src/list.ts uses the recursive mapHas helper to walk an archive entry path upward with path.dirname() and no segment cap when tar.t(...) or tar.x(...) receives a non-empty member-selection list. A crafted GNU L or PAX x long-path header with thousands of slash-separated segments reaches this.filter(entry.path, entry) in Parser[CONSUMEHEADER] in src/parse.ts before Unpack[CHECKPATH] applies maxDepth, causing an uncatchable RangeError stack overflow that terminates asynchronous and streaming Node.js consumers. This issue is fixed in version 7.5.21.
Remediation Steps
- Update the affected package
tar from version 7.5.16 to 7.5.21.
About this issue
- This issue may not contain all the information about the CVE nor the images it affects.
- This issue will not be updated with new information and the list of affected images may have changed since the creation of this issue.
- For more, visit Lambda Watchdog.
- This issue was created automatically by Lambda Watchdog.
CVE Details
HIGHtar7.5.167.5.212026-08-13T18:18:19.25Z2026-08-22T10:18:29.036623362ZAffected Docker Images
public.ecr.aws/lambda/nodejs:latestpublic.ecr.aws/lambda/nodejs@sha256:1ff82da6fcff5cb4d0518505aeba477acab4d5bc230e257ac3d0450a77fbc169public.ecr.aws/lambda/nodejs:24public.ecr.aws/lambda/nodejs@sha256:1ff82da6fcff5cb4d0518505aeba477acab4d5bc230e257ac3d0450a77fbc169public.ecr.aws/lambda/nodejs:22public.ecr.aws/lambda/nodejs@sha256:8e26dc1314af70609939e524f4474a3043a945bfe862779ef408deb2962ce945Description
Remediation Steps
tarfrom version7.5.16to7.5.21.About this issue