StackRadar

CVE-2026-59871

High

Advisory

Published 8 Jul 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
49th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
908
of 17,790 indexed, latest versions
Container images
934
deployed by those charts
Fix available
2 of 3
affected packages

node-tar: Process crash via PAX numeric path type confusion

Carried by container images the latest versions of 908 of 17,790 indexed charts deploy, on 934 images.

Affected packageAffected versionsFixed inImages
node-tardeb1.0.3-2, 2.2.1-1, 4.4.10+ds1-2ubuntu1, 6.1.13+~cs7.0.5-3+1 moreno fix listed7
tarnpm1.0.3, 2.2.1, 2.2.2, 4.0.2+32 more7.5.18934
npmapk11.17.0-r012.0.0-r11
OSV records
DEBIAN-CVE-2026-59871CGA-gf8f-xr4c-6j3hGHSA-w8wr-v893-vjvpUBUNTU-CVE-2026-59871
Also known as
CGA-hh5x-fg4g-9r6f

Charts affected

908 by stars
ChartLatestAffected imagesRadar Score
fspiop-transfer-api-svcmojaloop12.0.12 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

2 of the 3 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
mojaloop/event-sidecar:v11.0.189b8ab71b74b
tar@6.1.0
7.5.18
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
tar@4.4.13
7.5.18

Open the chart page →

11,546
mojaloopmojaloop14.0.04 of 6See more

mojaloop mojaloop 14.0.0

4 of the 6 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
tar@6.1.11
7.5.18
mojaloop/central-ledger:v13.14.01abc8a7aa71c
tar@4.4.13
7.5.18
mojaloop/event-sidecar:v11.0.189b8ab71b74b
tar@6.1.0
7.5.18
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
tar@4.4.13
7.5.18

Open the chart page →

19,293
reporting-aggregator-svcmojaloop1.0.71 of 1See more

reporting-aggregator-svc mojaloop 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
mojaloop/reporting-aggregator-svc:v0.0.92635baf23298
tar@6.2.1
7.5.18

Open the chart page →

801
reporting-events-processor-svcmojaloop3.5.31 of 1See more

reporting-events-processor-svc mojaloop 3.5.3

1 of the 1 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
tar@7.4.3
7.5.18

Open the chart page →

2,632
reporting-hub-bop-api-svcmojaloop4.1.31 of 1See more

reporting-hub-bop-api-svc mojaloop 4.1.3

1 of the 1 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-api-svc:v4.1.2b45a2d6f0f2a
tar@6.1.11
7.5.18

Open the chart page →

1,661
reporting-hub-bop-experience-api-svcmojaloop1.0.31 of 1See more

reporting-hub-bop-experience-api-svc mojaloop 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
tar@6.2.1
7.5.18

Open the chart page →

2,319
reporting-legacy-apimojaloop2.2.01 of 1See more

reporting-legacy-api mojaloop 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
mojaloop/reporting:v12.1.0d480a62103d6
tar@6.2.1
7.5.18

Open the chart page →

1,949
role-assignment-servicemojaloop3.1.01 of 1See more

role-assignment-service mojaloop 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
mojaloop/role-assignment-service:v2.1.0def4bf273721
tar@6.2.0
7.5.18

Open the chart page →

2,316
security-role-perm-operator-svcmojaloop3.0.01 of 1See more

security-role-perm-operator-svc mojaloop 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
tar@7.5.1
7.5.18

Open the chart page →

2,458
mongo-compassmongo-compass-web-helm1.1.01 of 1See more

mongo-compass mongo-compass-web-helm 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
haohanyang/compass-web:0.5.054f2112602ee
tar@7.5.13
7.5.18

Open the chart page →

2,419
mongodb-admin-interfacemongo-db-admin-interfaceVerified publisher0.1.01 of 2See more

mongodb-admin-interface mongo-db-admin-interface 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
library/mongo-express:latest1b23d7976f02
tar@6.2.1
7.5.18

Open the chart page →

5,220
sample-appmongodb-helm-charts0.1.01 of 2See more

sample-app mongodb-helm-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
tar@6.1.11
7.5.18

Open the chart page →

6,438
monocularmonocular1.4.151 of 5See more

monocular monocular 1.4.15

1 of the 5 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
migmartri/prerender:latest486aacfd5aa9
tar@2.2.1
7.5.18

Open the chart page →

7,048
monopolymonopolypackage0.1.01 of 1See more

monopoly monopolypackage 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
gonzague/monopoly:latest70465995deea
tar@6.1.11
7.5.18

Open the chart page →

1,130
api-proxymoreillonVerified publisher0.1.41 of 1See more

api-proxy moreillon 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
moreillon/api-proxy:2373c1953739ef6956b5
tar@6.1.11
7.5.18

Open the chart page →

1,711
camera-viewermoreillonVerified publisher0.2.11 of 4See more

camera-viewer moreillon 0.2.1

1 of the 4 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
moreillon/camera-proxy:latestce60056b50c2
tar@6.1.11
7.5.18

Open the chart page →

11,708
face-recognitionmoreillonVerified publisher0.2.41 of 3See more

face-recognition moreillon 0.2.4

1 of the 3 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
moreillon/face-recognition-fastapi-front:latestc1072f4ab6aa
tar@4.4.19
7.5.18

Open the chart page →

8,556
group-managermoreillonVerified publisher0.4.41 of 3See more

group-manager moreillon 0.4.4

1 of the 3 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
moreillon/group-manager:v4.9.0d5a0ec8394c0
tar@6.1.11
7.5.18

Open the chart page →

9,900
mqtt-loggermoreillonVerified publisher0.3.11 of 5See more

mqtt-logger moreillon 0.3.1

1 of the 5 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
moreillon/mqtt-logger:9ffbf7180a8a7daf56f6
tar@6.1.11
7.5.18

Open the chart page →

11,008
user-manager-mongodbmoreillonVerified publisher0.6.21 of 4See more

user-manager-mongodb moreillon 0.6.2

1 of the 4 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
tar@6.2.0
7.5.18

Open the chart page →

25,844
user-manager-neo4jmoreillonVerified publisher0.9.72 of 6See more

user-manager-neo4j moreillon 0.9.7

2 of the 6 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
moreillon/group-manager:v4.9.0d5a0ec8394c0
tar@6.1.11
7.5.18
moreillon/user-manager:v5.0.2e1c9bfab5c16
tar@6.1.13
7.5.18

Open the chart page →

30,524
sentence-collectormozilla0.1.21 of 2See more

sentence-collector mozilla 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
mozilla/sentencecollector:2.0.91da6ff5c4895
tar@4.4.13
7.5.18

Open the chart page →

6,684
tianjimsgbyte0.1.171 of 2See more

tianji msgbyte 0.1.17

1 of the 2 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
moonrailgun/tianji:1.11.2b528c8f8fcc4
tar@6.1.15
7.5.18

Open the chart page →

4,560
ghostmt1905028.25.11 of 3See more

ghost mt190502 8.25.1

1 of the 3 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
library/ghost:6.25.12654b1e90413
tar@7.5.11
7.5.18

Open the chart page →

4,982
nightscoutmt1905021.1.01 of 3See more

nightscout mt190502 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
tar@6.1.11
7.5.18

Open the chart page →

6,649
umamimt1905028.1.41 of 3See more

umami mt190502 8.1.4

1 of the 3 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
ghcr.io/umami-software/umami:3.0.328f263fe06f7
tar@7.5.2
7.5.18

Open the chart page →

4,041
cloudcmdmy0nVerified publisher0.0.31 of 1See more

cloudcmd my0n 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
coderaiser/cloudcmd:16.6.1b34a9775c7ce
tar@6.1.11
7.5.18

Open the chart page →

3,128
danboorumy0nVerified publisher0.0.21 of 1See more

danbooru my0n 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
tar@4.4.13
7.5.18

Open the chart page →

12,851
danbooru-stackmy0nVerified publisher0.0.31 of 4See more

danbooru-stack my0n 0.0.3

1 of the 4 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
tar@4.4.13
7.5.18

Open the chart page →

12,851
myawesomeappmyawesomapp-mitchxxx0.1.11 of 1See more

myawesomeapp myawesomapp-mitchxxx 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
mitchxxx/amazon:214e72480ec63a
tar@6.2.0
7.5.18

Open the chart page →

2,116
myawesomeappmyawesomeapp1.1.01 of 1See more

myawesomeapp myawesomeapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
ooghenekaro/nodejswebapp:latestea5b71588a76
tar@6.1.13
7.5.18

Open the chart page →

1,268
myawesomeapp14myawesomeapp140.1.11 of 1See more

myawesomeapp14 myawesomeapp14 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
ccjacobs14/amazon:59a9b14a6f09e
tar@6.2.0
7.5.18

Open the chart page →

2,116
myawesomeappmyawesomeapp20.1.01 of 1See more

myawesomeapp myawesomeapp2 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
mpopoola1/nodejsapp:latest061fc532de7d
tar@6.2.0
7.5.18

Open the chart page →

1,119
myawesomeapp-feb24myawesomeapp-feb240.1.11 of 1See more

myawesomeapp-feb24 myawesomeapp-feb24 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
josepht05/nodejs-feb24:latest36cb0c618c94
tar@6.2.0
7.5.18

Open the chart page →

1,070
myawesomeapp-janmyawesomeapp-jan0.1.11 of 1See more

myawesomeapp-jan myawesomeapp-jan 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
ooghenekaro/amazon:latest03394ba1d6d8
tar@6.1.13
7.5.18

Open the chart page →

2,144
myawesomeapp-marmyawesomeapp-mar0.1.11 of 1See more

myawesomeapp-mar myawesomeapp-mar 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
winfred008/amazon:910a68de5b398
tar@6.2.0
7.5.18

Open the chart page →

2,116
myawesomeappoctmyawesomeappoct0.1.11 of 1See more

myawesomeappoct myawesomeappoct 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
ooghenekaro/nodejswebappoct:lateste010f5fecbc7
tar@6.1.15
7.5.18

Open the chart page →

1,165
myawesomeappoctmyawesomeappoct20230.1.11 of 1See more

myawesomeappoct myawesomeappoct2023 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
hamid2021/nodejs-dockercli:latest429d99890c3c
tar@6.2.0
7.5.18

Open the chart page →

1,119
mydannyappmydannyapp1.1.01 of 1See more

mydannyapp mydannyapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
danny1dockerhub/nodejswebapp:lateste434683fcc89
tar@6.1.13
7.5.18

Open the chart page →

1,268
mygreatappmygreatapp0.1.01 of 1See more

mygreatapp mygreatapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
ktitilayo2/nodejswebapp:latest8bac28058688
tar@6.1.15
7.5.18

Open the chart page →

1,165
myhelmappmyhelm-app1.1.01 of 1See more

myhelmapp myhelm-app 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
patdada/bella-docker:v1.0.075127147a624
tar@4.4.19
7.5.18

Open the chart page →

1,625
myhelmappmyhelmapp0.1.11 of 1See more

myhelmapp myhelmapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
tobirachel/node-project3:v17d9f37154994
tar@6.1.14
7.5.18

Open the chart page →

3,366
myhelmappmyhelmapp11.1.01 of 1See more

myhelmapp myhelmapp1 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
josepht05/titajo-docker:v1.0.0d94024965d78
tar@6.1.15
7.5.18

Open the chart page →

1,165
myhelmappmyhelmpapp1.1.01 of 1See more

myhelmapp myhelmpapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
ooghenekaro/hans-docker:v1.0.0d1f972aa844a
tar@6.1.14
7.5.18

Open the chart page →

1,235
myweatherhelmmyweather1.3.111 of 7See more

myweatherhelm myweather 1.3.11

1 of the 7 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
tar@6.2.1
7.5.18

Open the chart page →

18,042
dashynas-helm-chartsVerified publisher1.0.41 of 1See more

dashy nas-helm-charts 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
lissy93/dashy:2.0.51991f7be5ed0
tar@6.1.11
7.5.18

Open the chart page →

3,270
smilencsaVerified publisher1.1.02 of 23See more

smile ncsa 1.1.0

2 of the 23 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
tar@4.4.2
7.5.18
socialmediamacroscope/smile_server:0.3.31a528c794270
tar@6.1.0
7.5.18

Open the chart page →

109,730
uptime-kumancsaVerified publisher1.7.21 of 1See more

uptime-kuma ncsa 1.7.2

1 of the 1 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.4917318f9d7be
tar@7.5.11
7.5.18

Open the chart page →

30,326
ixyneoskop2.1.11 of 1See more

ixy neoskop 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
neoskop/ixy:2.1.125152b474f54
tar@7.5.7
7.5.18

Open the chart page →

1,166
papergirlneoskop3.2.61 of 5See more

papergirl neoskop 3.2.6

1 of the 5 container images this version deploys carry CVE-2026-59871.

Container imageDigestPackageFixed in
neoskop/papergirl:3.2.67f52b5949f03
tar@6.1.15
7.5.18

Open the chart page →

6,989

Container images carrying it

934 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
tar@2.2.2
7.5.18
1
quay.io/ibmgaragecloud/nodejs:latest01c3b7acb301
tar@4.4.13
7.5.18
1
quay.io/ibmgaragecloud/slack-notifications:latest041df93e2bac
tar@4.4.13
7.5.18
1
quay.io/kuberay/dashboard:v1.7.07e43d4b4fd9f
tar@7.5.16
7.5.18
1
quay.io/maximilianopizarro/neuroface-backend:v1.4.13194d46df0f9
tar@7.5.11
7.5.18
1
quay.io/maximilianopizarro/neuroface-backend:latestcba71dc08c8a
tar@7.5.11
7.5.18
1
quay.io/mittwald/kube-mail:latest04f1099241fc
tar@6.2.1
7.5.18
1
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
tar@6.1.11
7.5.18
1
quay.io/netwarps/blockscoutbecd3e39360a
tar@6.1.11
7.5.18
1
quay.io/netwarps/walletconnect-relay:v2.1.3-rc.15d90b9c193e0
tar@6.1.11
7.5.18
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
tar@6.2.0
7.5.18
1
quay.io/renokico/laravel-helm-demo:0.6.03207f957e80c
tar@6.1.0
7.5.18
1
quay.io/renokico/laravel-helm-demo:worker-0.6.04b188259267e
tar@6.1.0
7.5.18
1
quay.io/renokico/laravel-helm-demo:octane-0.6.0cad83090c58f
tar@4.4.15
7.5.18
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
tar@4.4.13
7.5.18
1
quay.io/seamware/fdsc-dashboard:0.6.0f7706c316c5a
tar@6.2.1
7.5.18
1
quay.io/seamware/onboarding:0.2.2b406475f9f00
tar@7.5.11
7.5.18
1
quay.io/soketi/k8soketi:0.1-18-debian4cd9ea9434c4
tar@6.1.11
7.5.18
1
quay.io/soketi/pws:0.8-16-alpine399d2e6b10ef
tar@6.1.11
7.5.18
1
quay.io/soketi/soketi:1.6-16-debian713223456cf1
tar@6.1.11
7.5.18
1
quay.io/t3n/dashkiosk:v2.7.8c973e166a5dc
tar@4.4.13
7.5.18
1
quay.io/wekan/wekan:v5.65cb17600883a3
tar@6.1.11
7.5.18
1
quay.io/wi_stefan/consent-manager:0.0.656399619568b
tar@7.5.11
7.5.18
1
quay.io/wraft/wraft-frontend:latestf1bbbd5e9bb9
tar@6.2.1
7.5.18
1
registry.gitlab.com/dyff/dyff-frontend:0.20.2481be0beaafe
tar@6.2.1
7.5.18
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
tar@7.5.11
7.5.18
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
tar@6.2.1
7.5.18
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-user:1.0.31d8a9cd4e1ae3
tar@7.5.11
7.5.18
1
registry.gitlab.com/evolves-fr/s3-browser:0.4.1c350c941fe7b
tar@7.5.11
7.5.18
1
registry.gitlab.com/infinitydon/registry/open5gs-webui:v2.2.2fda21b0a0344
tar@4.4.13
7.5.18
1
registry.gitlab.com/timvisee/send:v3.4.2047986cf6ef69
tar@6.1.11
7.5.18
1
registry.gitlab.com/xrow-public/ci-tools/tools:main9b9d1ed86b6a
tar@7.5.11
7.5.18
1
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
tar@6.2.1
7.5.18
1
registry.gitlab.com/xrow-public/helm-openclaw/openclaw:1.91.3ed44d81a65de
tar@7.5.16
7.5.18
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.