StackRadar

CVE-2026-59873

Critical

Advisory

Published 8 Jul 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.2
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
906
of 17,787 indexed, latest versions
Container images
936
deployed by those charts
Fix available
2 of 3
affected packages

node-tar: Decompression/parse DoS via unlimited input

Carried by container images the latest versions of 906 of 17,787 indexed charts deploy, on 936 images.

Affected packageAffected versionsFixed inImages
npmapk11.17.0-r012.0.0-r11
tarnpm1.0.3, 2.2.1, 2.2.2, 4.0.2+32 more7.5.19936
node-tardeb1.0.3-2, 2.2.1-1, 4.4.10+ds1-2ubuntu1, 6.1.13+~cs7.0.5-3+1 moreno fix listed7
OSV records
CGA-hxjr-75xr-3m9cDEBIAN-CVE-2026-59873GHSA-23hp-3jrh-7fpwUBUNTU-CVE-2026-59873
Also known as
CGA-w28j-p9gq-x49x

Charts affected

906 by stars
ChartLatestAffected imagesRadar Score
workadventureworkadventure1.1.04 of 9See more

workadventure workadventure 1.1.0

4 of the 9 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-back:v1.17.764001369dad5
tar@6.1.11
7.5.19
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
tar@6.1.11
7.5.19
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
tar@6.1.11
7.5.19
thecodingmachine/workadventure-uploader:v1.17.73ccd467543b3
tar@6.1.11
7.5.19

Open the chart page →

16,083
skoonerxdVerified publisher1.1.01 of 1See more

skooner xd 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
ymuski/skooner:latest67819ca511b5
tar@4.4.19
7.5.19

Open the chart page →

1,752
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
tar@6.2.1
7.5.19

Open the chart page →

9,381
helloworldyotron-helm-charts0.1.01 of 1See more

helloworld yotron-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
a5hut0sh/helloworld:1.02ae77620e616
tar@4.4.8
7.5.19

Open the chart page →

1,309
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
tar@6.1.14
7.5.19

Open the chart page →

1,588
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
zl0i/alertmanager-matrix-forwarder:v1.0.0e94047931739
tar@6.1.11
7.5.19

Open the chart page →

3,118

Container images carrying it

936 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
felipecs8/landing-page:v1db6d44e325a1
tar@6.2.1
7.5.19
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
tar@6.2.1
7.5.19
1
fiware/idm:8.3.3a1b6ed4ae84f
tar@4.4.19
7.5.19
1
fiware/iotagent-json:3.1.0879b21a0d36d
tar@6.1.11
7.5.19
1
fiware/iotagent-ul:1.14.0fe11f55a926d
tar@4.4.13
7.5.19
1
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
tar@4.4.13
7.5.19
1
flanksource/canary-checker-ui:v1.4.281764c84e550db
tar@7.4.3
7.5.19
1
flanksource/incident-manager-ui:v1.4.318891f21df54fb
tar@7.4.3
7.5.19
1
folioci/mod-graphql:latestf0655a6a08fd
tar@6.2.1
7.5.19
1
fonoster/routr-pgdata-migrations:2.13.6c7b1dba81eb3
tar@6.2.1
7.5.19
1
fosrl/pangolin:latest83a55f933b4d
tar@7.5.15
7.5.19
1
fosrl/pangolin:1.13.0c32ad797ab96
tar@7.5.2
7.5.19
1
frappe/frappe-socketio:v13.4.12095767a9e82
tar@6.1.0
7.5.19
1
freikin/dawarich:1.14.511826c67e4b1
node-tar@6.2.1+~cs7.0.8-1+deb13u1
tar@6.2.1
no fix listed
7.5.19
1
fthomas/scala-steward:latest367afe974b7a
tar@7.5.11
7.5.19
1
galaxy/galaxy-init:v18.010267bad550e6
tar@4.0.2
7.5.19
1
gethue/hue:4.11.011b649636e68
tar@4.4.19
7.5.19
1
gethue/hue:4.10.05702b2c37ff9
tar@4.4.13
7.5.19
1
gethue/hue:latest7d5c1b9f8a79
tar@7.5.4
7.5.19
1
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
tar@7.5.11
7.5.19
1
glenndehaan/api-mapper:latest6ff6310683bf
tar@6.2.0
7.5.19
1
glenndehaan/contentbridge:latest99b9e4f73848
tar@6.1.13
7.5.19
1
glenndehaan/kube-hook:latest0a7116f48bfe
tar@7.4.3
7.5.19
1
globalping/globalping-probe:latest8acbd23009fd
tar@7.5.11
7.5.19
1
gonzague/monopoly:latest70465995deea
tar@6.1.11
7.5.19
1
governify/collector-dynamic:v1.3.06d3d1a5b46a9
tar@4.4.19
7.5.19
1
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
tar@4.4.13
7.5.19
1
gristlabs/grist:0.7.96e71b1914a7e
tar@4.4.13
7.5.19
1
gtato/demo-multiclus-registrator:1.0.09a744588fab3
tar@6.1.11
7.5.19
1
gtato/demo-multiclus-registry:1.0.02df5174f3cfd
tar@6.1.11
7.5.19
1
halkeye/gitter-slack-bridge:v2.0.153eb2b3cd4cb
tar@4.4.13
7.5.19
1
halkeye/hubot:latest9764d2202130
tar@4.4.13
7.5.19
1
halkeye/irslackd:latest7638bfba70b0
tar@2.2.1
7.5.19
1
hamid2021/nodejs-dockercli:latest429d99890c3c
tar@6.2.0
7.5.19
1
hansehe/graphql-gateway:1.0.458e09540afbc
tar@6.1.15
7.5.19
1
haohanyang/compass-web:0.5.054f2112602ee
tar@7.5.13
7.5.19
1
haveagitgat/tdarr_node:2.00.101e3f9328327d
tar@4.4.13
7.5.19
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
tar@6.1.14
7.5.19
1
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
tar@6.2.1
7.5.19
1
helga09/shoes_ukr:v1.1.17999bc8b77c0
tar@6.1.14
7.5.19
1
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
tar@6.1.15
7.5.19
1
helmforge/opencut:v0.3.0bf11156e0ab5
tar@7.5.16
7.5.19
1
heywood8/redisinsight:2.28.00bc9ab313d37
tar@6.1.13
7.5.19
1
hhaluk/crypto-watchdog:0.4.0a6555953d941
tar@4.4.13
7.5.19
1
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
tar@7.4.3
7.5.19
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
tar@6.1.11
7.5.19
1
honglab/slack-emoji-maker:v0.0.1ca075a926fe1
tar@6.2.1
7.5.19
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
tar@6.2.1
7.5.19
1
hugohg34/server:0.0.2503e5d8960ff
tar@6.1.11
7.5.19
1
hyperledger/fabric-couchdb:0.4.10c65891b6c237
tar@2.2.1
7.5.19
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.