StackRadar

CVE-2026-59871

High

Advisory

Published 8 Jul 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
49th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
901
of 17,790 indexed, latest versions
Container images
926
deployed by those charts
Fix available
2 of 3
affected packages

node-tar: Process crash via PAX numeric path type confusion

Carried by container images the latest versions of 901 of 17,790 indexed charts deploy, on 926 images.

Affected packageAffected versionsFixed inImages
node-tardeb1.0.3-2, 2.2.1-1, 4.4.10+ds1-2ubuntu1, 6.1.13+~cs7.0.5-3+1 moreno fix listed7
tarnpm1.0.3, 2.2.1, 2.2.2, 4.0.2+32 more7.5.18926
npmapk11.17.0-r012.0.0-r11
OSV records
DEBIAN-CVE-2026-59871CGA-gf8f-xr4c-6j3hGHSA-w8wr-v893-vjvpUBUNTU-CVE-2026-59871
Also known as
CGA-hh5x-fg4g-9r6f

Charts affected

901 by stars
ChartLatestAffected imagesRadar Score
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
zl0i/alertmanager-matrix-forwarder:v1.0.0e94047931739
tar@6.1.11
7.5.18

Open the chart page →

3,118

Container images carrying it

926 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ooghenekaro/hans-docker:v1.0.0d1f972aa844a
tar@6.1.14
7.5.18
1
ooghenekaro/nodejswebapp:latestea5b71588a76
tar@6.1.13
7.5.18
1
ooghenekaro/nodejswebappoct:lateste010f5fecbc7
tar@6.1.15
7.5.18
1
opea/codegen-ui:1.02bee4eb66f3e
tar@6.2.0
7.5.18
1
opea/codetrans-ui:1.03ef121f34610
tar@6.2.0
7.5.18
1
opea/docsum-ui:1.07f854e9bffaf
tar@6.2.0
7.5.18
1
openbas/caldera-server:5.1.0a277796d9724
tar@6.2.0
7.5.18
1
opencti/platform:7.260910.0186fc757c3eb
tar@7.5.11
7.5.18
1
opendatacube/wps:latest80df355a660b
tar@7.4.3
7.5.18
1
openemr/openemr:6.1.089eaa6d9a4e3
tar@6.1.11
7.5.18
1
openhab/openhab-cloud:a8138a329dd2bac8c4b
tar@6.1.0
7.5.18
1
openmined/syft-frontend:0.9.5d11524a3854a
tar@7.4.3
7.5.18
1
openproject/community:12.0.2734743d11094
tar@4.4.13
7.5.18
1
openproject/hocuspocus:release-338001b288dc1359dfb5
tar@6.2.1
7.5.18
1
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
tar@6.2.1
7.5.18
1
opensearchproject/opensearch-dashboards:2.10.0485a0019e5d6
tar@6.1.13
7.5.18
1
opensearchproject/opensearch-dashboards:2.15.0b7c26c60bfaf
tar@6.2.1
7.5.18
1
openthread/otbr:latestf307f59f6432
node-tar@2.2.1-1
tar@2.2.1
no fix listed
7.5.18
1
openwhisk/alarmprovider:2.2.0b695a6ceb406
tar@4.4.13
7.5.18
1
openwhisk/ow-utils:1.0.0c80dba0de3aa
node-tar@2.2.1-1
tar@2.2.1
no fix listed
7.5.18
1
oryd/hive-selfservice-ui-node:v0.0.426347ef0a2de
tar@4.4.12
7.5.18
1
oryd/hydra-login-consent-node:v26.2.06465e95993b5
tar@7.4.3
7.5.18
1
oryd/kratos-selfservice-ui-node:v26.2.046a7bac1ad0c
tar@6.1.11
7.5.18
1
oryd/kratos-selfservice-ui-node:v0.13.0-20d454c21c11bc
tar@6.1.11
7.5.18
1
otwld/velero-ui:0.10.2d1954b759e47
tar@7.5.11
7.5.18
1
outlinewiki/outline:0.82.0494dfb9249a6
tar@6.2.1
7.5.18
1
outlinewiki/outline:1.10.1832051f039b4
tar@7.5.15
7.5.18
1
pachyderm/grpc-proxy:0.4.92b27f41d4d02
tar@4.4.6
7.5.18
1
parithoshj/testnet-faucet:9859e0dcdca426fea6d
tar@4.4.13
7.5.18
1
patdada/bella-docker:v1.0.075127147a624
tar@4.4.19
7.5.18
1
patrickhulce/lhci-server:0.8.174b4b6a3954d
tar@4.4.13
7.5.18
1
pawelmalak/flame:2.1.193e7b0abb603
tar@6.1.11
7.5.18
1
pawelmalak/flame:multiarch2.3.19f88b17692a0
tar@6.1.11
7.5.18
1
penpotapp/exporter:2.2.15c835ffd87ab
tar@6.2.1
7.5.18
1
penpotapp/exporter:2.17.272a8061e8806
tar@7.5.16
7.5.18
1
penpotapp/mcp:2.17.284f3f07ead11
tar@7.5.15
7.5.18
1
phntom/camo:2.3.1a9b1304d6c71
tar@4.4.15
7.5.18
1
phntom/codimd:2.4.31b9aafbb62e6
tar@5.0.11
7.5.18
1
phpdockerio/readability-js-server:1.8.0ea8354b42600
tar@7.5.1
7.5.18
1
plumdog/db-operator:latest0c2fa2db0357
tar@6.1.11
7.5.18
1
polonel/trudesk:1.2.60cf6513f6fe3
tar@6.1.11
7.5.18
1
pretix/standalone:2026.7.05df3b7aa852e
tar@7.5.11
7.5.18
1
project2team4/react:latest3ff031a08887
tar@4.4.19
7.5.18
1
promasu/cryptpad:v4.14.1-nginx51d1142b9f95
tar@6.1.11
7.5.18
1
prowlercloud/prowler-ui:5.31.179ee83c8e702
tar@7.5.1
7.5.18
1
pschiffe/pdns-admin:0.4.137ebba8c2b8f
tar@6.2.1
7.5.18
1
psorab/elibrary:latest53b68896c4ce
tar@6.1.11
7.5.18
1
pumejlab/nodejs-webapp:latestf563eabcb819
tar@6.1.15
7.5.18
1
punkerside/noroot:v0.0.7be20c81d6ca1
tar@6.1.11
7.5.18
1
qxip/qryn:3.2.3977acc9c7a9fd
tar@6.2.1
7.5.18
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.