CVE-2026-59873: node-tar: Decompression/parse DoS via unlimited input
A Decompression/parse DoS via unlimited input vulnerability in node-tar allows an attacker to exhaust server resources (disk space and CPU). Because the library does not enforce hard upper bounds on total decompressed data or entry counts, a small, maliciously crafted “Gzip Bomb” can be used to fill a server’s storage and crash services.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-59873 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →