StackRadar

CVE-2026-59873

Critical

Advisory

Published 8 Jul 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.2
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
906
of 17,787 indexed, latest versions
Container images
936
deployed by those charts
Fix available
2 of 3
affected packages

node-tar: Decompression/parse DoS via unlimited input

Carried by container images the latest versions of 906 of 17,787 indexed charts deploy, on 936 images.

Affected packageAffected versionsFixed inImages
npmapk11.17.0-r012.0.0-r11
tarnpm1.0.3, 2.2.1, 2.2.2, 4.0.2+32 more7.5.19936
node-tardeb1.0.3-2, 2.2.1-1, 4.4.10+ds1-2ubuntu1, 6.1.13+~cs7.0.5-3+1 moreno fix listed7
OSV records
CGA-hxjr-75xr-3m9cDEBIAN-CVE-2026-59873GHSA-23hp-3jrh-7fpwUBUNTU-CVE-2026-59873
Also known as
CGA-w28j-p9gq-x49x

Charts affected

906 by stars
ChartLatestAffected imagesRadar Score
reporting-aggregator-svcmojaloop1.0.71 of 1See more

reporting-aggregator-svc mojaloop 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
mojaloop/reporting-aggregator-svc:v0.0.92635baf23298
tar@6.2.1
7.5.19

Open the chart page →

800
reporting-events-processor-svcmojaloop3.5.31 of 1See more

reporting-events-processor-svc mojaloop 3.5.3

1 of the 1 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
tar@7.4.3
7.5.19

Open the chart page →

2,632
reporting-hub-bop-api-svcmojaloop4.1.31 of 1See more

reporting-hub-bop-api-svc mojaloop 4.1.3

1 of the 1 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-api-svc:v4.1.2b45a2d6f0f2a
tar@6.1.11
7.5.19

Open the chart page →

1,661
reporting-hub-bop-experience-api-svcmojaloop1.0.31 of 1See more

reporting-hub-bop-experience-api-svc mojaloop 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
tar@6.2.1
7.5.19

Open the chart page →

2,318
reporting-legacy-apimojaloop2.2.01 of 1See more

reporting-legacy-api mojaloop 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
mojaloop/reporting:v12.1.0d480a62103d6
tar@6.2.1
7.5.19

Open the chart page →

1,949
role-assignment-servicemojaloop3.1.01 of 1See more

role-assignment-service mojaloop 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
mojaloop/role-assignment-service:v2.1.0def4bf273721
tar@6.2.0
7.5.19

Open the chart page →

2,316
security-role-perm-operator-svcmojaloop3.0.01 of 1See more

security-role-perm-operator-svc mojaloop 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
tar@7.5.1
7.5.19

Open the chart page →

2,458
mongo-compassmongo-compass-web-helm1.1.01 of 1See more

mongo-compass mongo-compass-web-helm 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
haohanyang/compass-web:0.5.054f2112602ee
tar@7.5.13
7.5.19

Open the chart page →

2,306
mongodb-admin-interfacemongo-db-admin-interfaceVerified publisher0.1.01 of 2See more

mongodb-admin-interface mongo-db-admin-interface 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
library/mongo-express:latest1b23d7976f02
tar@6.2.1
7.5.19

Open the chart page →

5,217
sample-appmongodb-helm-charts0.1.01 of 2See more

sample-app mongodb-helm-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
tar@6.1.11
7.5.19

Open the chart page →

6,438
monocularmonocular1.4.151 of 5See more

monocular monocular 1.4.15

1 of the 5 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
migmartri/prerender:latest486aacfd5aa9
tar@2.2.1
7.5.19

Open the chart page →

7,048
monopolymonopolypackage0.1.01 of 1See more

monopoly monopolypackage 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
gonzague/monopoly:latest70465995deea
tar@6.1.11
7.5.19

Open the chart page →

1,130
api-proxymoreillonVerified publisher0.1.41 of 1See more

api-proxy moreillon 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
moreillon/api-proxy:2373c1953739ef6956b5
tar@6.1.11
7.5.19

Open the chart page →

1,712
camera-viewermoreillonVerified publisher0.2.11 of 4See more

camera-viewer moreillon 0.2.1

1 of the 4 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
moreillon/camera-proxy:latestce60056b50c2
tar@6.1.11
7.5.19

Open the chart page →

11,694
face-recognitionmoreillonVerified publisher0.2.41 of 3See more

face-recognition moreillon 0.2.4

1 of the 3 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
moreillon/face-recognition-fastapi-front:latestc1072f4ab6aa
tar@4.4.19
7.5.19

Open the chart page →

8,556
group-managermoreillonVerified publisher0.4.41 of 3See more

group-manager moreillon 0.4.4

1 of the 3 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
moreillon/group-manager:v4.9.0d5a0ec8394c0
tar@6.1.11
7.5.19

Open the chart page →

9,886
mqtt-loggermoreillonVerified publisher0.3.11 of 5See more

mqtt-logger moreillon 0.3.1

1 of the 5 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
moreillon/mqtt-logger:9ffbf7180a8a7daf56f6
tar@6.1.11
7.5.19

Open the chart page →

10,998
user-manager-mongodbmoreillonVerified publisher0.6.21 of 4See more

user-manager-mongodb moreillon 0.6.2

1 of the 4 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
tar@6.2.0
7.5.19

Open the chart page →

23,263
user-manager-neo4jmoreillonVerified publisher0.9.72 of 6See more

user-manager-neo4j moreillon 0.9.7

2 of the 6 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
moreillon/group-manager:v4.9.0d5a0ec8394c0
tar@6.1.11
7.5.19
moreillon/user-manager:v5.0.2e1c9bfab5c16
tar@6.1.13
7.5.19

Open the chart page →

30,195
sentence-collectormozilla0.1.21 of 2See more

sentence-collector mozilla 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
mozilla/sentencecollector:2.0.91da6ff5c4895
tar@4.4.13
7.5.19

Open the chart page →

6,684
tianjimsgbyte0.1.171 of 2See more

tianji msgbyte 0.1.17

1 of the 2 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
moonrailgun/tianji:1.11.2b528c8f8fcc4
tar@6.1.15
7.5.19

Open the chart page →

4,560
ghostmt1905028.25.11 of 3See more

ghost mt190502 8.25.1

1 of the 3 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
library/ghost:6.25.12654b1e90413
tar@7.5.11
7.5.19

Open the chart page →

4,908
nightscoutmt1905021.1.01 of 3See more

nightscout mt190502 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
tar@6.1.11
7.5.19

Open the chart page →

6,646
umamimt1905028.1.41 of 3See more

umami mt190502 8.1.4

1 of the 3 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
ghcr.io/umami-software/umami:3.0.328f263fe06f7
tar@7.5.2
7.5.19

Open the chart page →

4,030
cloudcmdmy0nVerified publisher0.0.31 of 1See more

cloudcmd my0n 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
coderaiser/cloudcmd:16.6.1b34a9775c7ce
tar@6.1.11
7.5.19

Open the chart page →

3,128
danboorumy0nVerified publisher0.0.21 of 1See more

danbooru my0n 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
tar@4.4.13
7.5.19

Open the chart page →

12,861
danbooru-stackmy0nVerified publisher0.0.31 of 4See more

danbooru-stack my0n 0.0.3

1 of the 4 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
tar@4.4.13
7.5.19

Open the chart page →

12,861
myawesomeappmyawesomapp-mitchxxx0.1.11 of 1See more

myawesomeapp myawesomapp-mitchxxx 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
mitchxxx/amazon:214e72480ec63a
tar@6.2.0
7.5.19

Open the chart page →

2,116
myawesomeappmyawesomeapp1.1.01 of 1See more

myawesomeapp myawesomeapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
ooghenekaro/nodejswebapp:latestea5b71588a76
tar@6.1.13
7.5.19

Open the chart page →

1,267
myawesomeapp14myawesomeapp140.1.11 of 1See more

myawesomeapp14 myawesomeapp14 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
ccjacobs14/amazon:59a9b14a6f09e
tar@6.2.0
7.5.19

Open the chart page →

2,116
myawesomeappmyawesomeapp20.1.01 of 1See more

myawesomeapp myawesomeapp2 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
mpopoola1/nodejsapp:latest061fc532de7d
tar@6.2.0
7.5.19

Open the chart page →

1,118
myawesomeapp-feb24myawesomeapp-feb240.1.11 of 1See more

myawesomeapp-feb24 myawesomeapp-feb24 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
josepht05/nodejs-feb24:latest36cb0c618c94
tar@6.2.0
7.5.19

Open the chart page →

1,070
myawesomeapp-janmyawesomeapp-jan0.1.11 of 1See more

myawesomeapp-jan myawesomeapp-jan 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
ooghenekaro/amazon:latest03394ba1d6d8
tar@6.1.13
7.5.19

Open the chart page →

2,144
myawesomeapp-marmyawesomeapp-mar0.1.11 of 1See more

myawesomeapp-mar myawesomeapp-mar 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
winfred008/amazon:910a68de5b398
tar@6.2.0
7.5.19

Open the chart page →

2,116
myawesomeappoctmyawesomeappoct0.1.11 of 1See more

myawesomeappoct myawesomeappoct 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
ooghenekaro/nodejswebappoct:lateste010f5fecbc7
tar@6.1.15
7.5.19

Open the chart page →

1,164
myawesomeappoctmyawesomeappoct20230.1.11 of 1See more

myawesomeappoct myawesomeappoct2023 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
hamid2021/nodejs-dockercli:latest429d99890c3c
tar@6.2.0
7.5.19

Open the chart page →

1,118
mydannyappmydannyapp1.1.01 of 1See more

mydannyapp mydannyapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
danny1dockerhub/nodejswebapp:lateste434683fcc89
tar@6.1.13
7.5.19

Open the chart page →

1,267
mygreatappmygreatapp0.1.01 of 1See more

mygreatapp mygreatapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
ktitilayo2/nodejswebapp:latest8bac28058688
tar@6.1.15
7.5.19

Open the chart page →

1,164
myhelmappmyhelm-app1.1.01 of 1See more

myhelmapp myhelm-app 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
patdada/bella-docker:v1.0.075127147a624
tar@4.4.19
7.5.19

Open the chart page →

1,625
myhelmappmyhelmapp0.1.11 of 1See more

myhelmapp myhelmapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
tobirachel/node-project3:v17d9f37154994
tar@6.1.14
7.5.19

Open the chart page →

3,359
myhelmappmyhelmapp11.1.01 of 1See more

myhelmapp myhelmapp1 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
josepht05/titajo-docker:v1.0.0d94024965d78
tar@6.1.15
7.5.19

Open the chart page →

1,164
myhelmappmyhelmpapp1.1.01 of 1See more

myhelmapp myhelmpapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
ooghenekaro/hans-docker:v1.0.0d1f972aa844a
tar@6.1.14
7.5.19

Open the chart page →

1,235
myweatherhelmmyweather1.3.111 of 7See more

myweatherhelm myweather 1.3.11

1 of the 7 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
tar@6.2.1
7.5.19

Open the chart page →

17,411
dashynas-helm-chartsVerified publisher1.0.41 of 1See more

dashy nas-helm-charts 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
lissy93/dashy:2.0.51991f7be5ed0
tar@6.1.11
7.5.19

Open the chart page →

3,270
smilencsaVerified publisher1.1.02 of 23See more

smile ncsa 1.1.0

2 of the 23 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
tar@4.4.2
7.5.19
socialmediamacroscope/smile_server:0.3.31a528c794270
tar@6.1.0
7.5.19

Open the chart page →

109,485
uptime-kumancsaVerified publisher1.7.21 of 1See more

uptime-kuma ncsa 1.7.2

1 of the 1 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.4917318f9d7be
tar@7.5.11
7.5.19

Open the chart page →

29,687
ixyneoskop2.1.11 of 1See more

ixy neoskop 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
neoskop/ixy:2.1.125152b474f54
tar@7.5.7
7.5.19

Open the chart page →

1,166
papergirlneoskop3.2.61 of 5See more

papergirl neoskop 3.2.6

1 of the 5 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
neoskop/papergirl:3.2.67f52b5949f03
tar@6.1.15
7.5.19

Open the chart page →

6,982
neosyncneosyncVerified publisher0.5.411 of 3See more

neosync neosync 0.5.41

1 of the 3 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
ghcr.io/nucleuscloud/neosync/app:0.5.41ca31ec35b829
tar@6.2.1
7.5.19

Open the chart page →

7,056
appneosync-appVerified publisher0.5.411 of 1See more

app neosync-app 0.5.41

1 of the 1 container images this version deploys carry CVE-2026-59873.

Container imageDigestPackageFixed in
ghcr.io/nucleuscloud/neosync/app:0.5.41ca31ec35b829
tar@6.2.1
7.5.19

Open the chart page →

1,569

Container images carrying it

936 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
koumoul/openapi-viewer:18eeca2e8285b
tar@2.2.1
7.5.19
1
ktitilayo2/nodejswebapp:latest8bac28058688
tar@6.1.15
7.5.19
1
kubebb/bff-server:v0.2.0-202312040fbb732379bc
tar@6.1.11
7.5.19
1
kubebb/component-store:latestfd8ecbd73213
tar@6.2.0
7.5.19
1
kubebb/tamp-portal:v5.6.0fadac6d52470
tar@4.4.13
7.5.19
1
kubebb/tdsf-portal:v5.7.0258458311bc9
tar@4.4.13
7.5.19
1
kubeflownotebookswg/centraldashboard:v1.6.137300551dea6
tar@4.4.19
7.5.19
1
kubeflownotebookswg/centraldashboard:v1.9.2af55c22ef5de
tar@6.1.11
7.5.19
1
kubegems/chatgpt-api:latestf3c492a938ad
tar@6.1.11
7.5.19
1
kubesphere/examples-bookinfo-ratings-v1:1.13.0f1b5bf878196
tar@4.4.8
7.5.19
1
kubevious/backend:1.2.22d9ba6eb46b6
tar@6.2.0
7.5.19
1
kubevious/collector:1.2.1f58226f9d84e
tar@6.1.13
7.5.19
1
kubevious/guard:1.2.19bf567704de2
tar@4.4.19
7.5.19
1
kubevious/parser:1.0.151acf1a1f0b47
tar@4.4.19
7.5.19
1
kubevious/parser:1.2.299ae7a5168c2
tar@6.1.15
7.5.19
1
kubevious/workload-operator:1.0.20b0f4c507eb6
tar@4.4.19
7.5.19
1
kvalitetsit/kithosting-networkpolicytests:0.0.12b99cfa3c5df
tar@4.4.13
7.5.19
1
kyleslugg/klusterview:latestba8c36dfdfbd
tar@6.1.11
7.5.19
1
kyso/kyso-front:lateste52595c5c16f
tar@6.1.11
7.5.19
1
laly9999/node-app:1dd0e503913e1
tar@6.2.1
7.5.19
1
laly9999/node-app-dockerized:latest75ae77a20c6c
tar@6.2.0
7.5.19
1
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
tar@7.4.3
7.5.19
1
langgenius/dify-api:1.16.1dcefa5f7c47c
tar@7.4.3
7.5.19
1
langgenius/dify-ee-enterprise-frontend:3.9.8-ubi98dd9de6b6190
tar@7.5.15
7.5.19
1
langgenius/dify-ee-web:3.9.8-ubi9ba1dd1d0bcea
tar@7.5.15
7.5.19
1
langgenius/dify-sandbox:0.2.124e65e8a351a2
tar@6.2.0
7.5.19
1
langgenius/dify-web:1.16.187dd47e4e28f
tar@7.4.3
7.5.19
1
langgenius/dify-web:0.6.11a2a294743634
tar@6.2.0
7.5.19
1
langgenius/dify-web:1.10.1-fix.1c306ac577912
tar@6.2.1
7.5.19
1
langgenius/dify-web:1.0.0d64914ff0d6d
tar@6.2.1
7.5.19
1
lavandadelpatio/frontend:latest501c3f31e0bc
tar@4.4.8
7.5.19
1
lbenicio/helm-pilot:0.2.54594a2632510
tar@7.5.11
7.5.19
1
lbenicio/stremio-web:latest732f9003de33
tar@7.5.11
7.5.19
1
leeyoongti/first-app:1.0.021d66cb76352
tar@4.4.13
7.5.19
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
tar@6.2.1
7.5.19
1
library/ghost:6.37.01ef2e532ca4d
tar@7.5.11
7.5.19
1
library/ghost:6.25.12654b1e90413
tar@7.5.11
7.5.19
1
library/ghost:6.41.129773d6be407
tar@7.5.13
7.5.19
1
library/ghost:4.37.0767230c0f263
tar@6.1.11
7.5.19
1
library/ghost:6.39.0-alpine77196da4b0df
tar@7.5.15
7.5.19
1
library/ghost:5.79.083f7bf209844
tar@6.1.14
7.5.19
1
library/ghost:6.62.0a7a268bbfb7f
tar@7.5.16
7.5.19
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
tar@7.4.3
7.5.19
1
library/kibana:7.17.150172f1c538e7
tar@6.1.15
7.5.19
1
library/kibana:8.18.004c0fc150f3a
tar@7.4.3
7.5.19
1
library/kibana:7.17.8c5781ba340ef
tar@6.1.11
7.5.19
1
library/kibana:7.17.3e2e2031c15be
tar@6.1.11
7.5.19
1
library/mongo-express:1.0.2-20-alpine3.191aae00775251
tar@6.2.1
7.5.19
1
library/node:16.13.0-alpine60ef0bed1dc2
tar@6.1.11
7.5.19
1
library/node:22-bookworm-slim83f487e0a634
tar@7.5.11
7.5.19
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.