CVE-2026-29786

high Red Hat
CVSS v3 Base Score
8.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Published: March 7, 2026
Last Modified: March 7, 2026
Vendor: Red Hat

Description

node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction directory by using a drive-relative link target such as C:../target.txt, which enables file overwrite outside cwd during normal tar.x() extraction. This issue has been patched in version 7.5.10.

CWE

CWE-22

Affected Products

Cryostat 4Logging Subsystem for Red Hat OpenShiftNetwork Observability OperatorRed Hat 3scale API Management Platform 2Red Hat Advanced Cluster Management for Kubernetes 2Red Hat AMQ Broker 7Red Hat build of Apache Camel - HawtIO 4Red Hat Enterprise Linux 10Red Hat Enterprise Linux 8Red Hat Enterprise Linux 9

References