CVE-2026-24842

Vulnerability

CVE-2026-24842

node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check

ecosystem: redhat:8, redhat:9, redhat:10

A flaw was found in node-tar, a Node.js module for handling TAR archives. This vulnerability allows a remote attacker to bypass path traversal protections by crafting a malicious TAR archive. The security check for hardlink entries uses different path resolution logic than the actual hardlink creation, enabling the attacker to create hardlinks to arbitrary files outside the intended extraction directory. This could lead to unauthorized information disclosure or further system compromise.

References
severityI
Important

type: vendor

source: secalert@redhat.com

CVSS3.1
8.2HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N

AVNetwork
ACLow
PRNone
UIRequired
SChanged
CHigh
ILow
ANone

source: secalert@redhat.com

 CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')

source: secalert@redhat.com

published: 2026-01-28 00:20:13

modified: 2026-02-02 08:21:00

Detection

redhat:10
CVE-2026-24842

redhat-vex

OR

unfixedAffected

 

nodejs

package type: binary

type: version
unfixedAffected

 

nodejs-devel

package type: binary

type: version
unfixedAffected

 

nodejs-docs

package type: binary

type: version
unfixedAffected

 

nodejs-full-i18n

package type: binary

type: version
unfixedAffected

 

nodejs-libs

package type: binary

type: version
unfixedAffected

 

nodejs-npm

package type: binary

type: version
unfixedAffected

 

sgx-common

package type: binary

type: version
unfixedAffected

 

sgx-libs

package type: binary

type: version
unfixedAffected

 

sgx-mpa

package type: binary

type: version
unfixedAffected

 

sgx-pckid-tool

package type: binary

type: version
unfixedAffected

 

tdx-qgs

package type: binary

type: version
unfixedAffected

 

nodejs22

package type: source

type: version

tag: rhel-10:b80bcfb1-921f-0310-88a1-5d0eaf9eecb5

redhat:8
CVE-2026-24842

redhat-vex

OR

unfixedAffected

 

grafana

package type: binary

type: version
unfixedAffected

 

grafana-azure-monitor

package type: binary

type: version
unfixedAffected

 

grafana-cloudwatch

package type: binary

type: version
unfixedAffected

 

grafana-elasticsearch

package type: binary

type: version
unfixedAffected

 

grafana-graphite

package type: binary

type: version
unfixedAffected

 

grafana-influxdb

package type: binary

type: version
unfixedAffected

 

grafana-loki

package type: binary

type: version
unfixedAffected

 

grafana-mssql

package type: binary

type: version
unfixedAffected

 

grafana-mysql

package type: binary

type: version
unfixedAffected

 

grafana-opentsdb

package type: binary

type: version
unfixedAffected

 

grafana-postgres

package type: binary

type: version
unfixedAffected

 

grafana-prometheus

package type: binary

type: version
unfixedAffected

 

grafana-selinux

package type: binary

type: version
unfixedAffected

 

grafana-stackdriver

package type: binary

type: version
unfixedAffected

 

grafana

package type: source

type: version

tag: rhel-8-including-unpatched:a6618379-c998-bcc2-6548-61c943711fea

redhat:9
CVE-2026-24842

redhat-vex

OR

unfixedAffected

 

grafana

package type: binary

type: version
unfixedAffected

 

grafana-selinux

package type: binary

type: version
unfixedAffected

 

nodejs:20::nodejs

package type: binary

type: version
unfixedAffected

 

nodejs:20::nodejs-docs

package type: binary

type: version
unfixedAffected

 

nodejs:20::nodejs-full-i18n

package type: binary

type: version
unfixedAffected

 

nodejs:20::nodejs-libs

package type: binary

type: version
unfixedAffected

 

nodejs:20::npm

package type: binary

type: version
unfixedAffected

 

nodejs:22::nodejs

package type: binary

type: version
unfixedAffected

 

nodejs:22::nodejs-docs

package type: binary

type: version
unfixedAffected

 

nodejs:22::nodejs-full-i18n

package type: binary

type: version
unfixedAffected

 

nodejs:22::nodejs-libs

package type: binary

type: version
unfixedAffected

 

nodejs:22::npm

package type: binary

type: version
unfixedAffected

 

polkit-devel

package type: binary

type: version
unfixedAffected

 

polkit-docs

package type: binary

type: version
unfixedAffected

 

polkit-libs

package type: binary

type: version
unfixedAffected

 

sgx-common

package type: binary

type: version
unfixedAffected

 

sgx-libs

package type: binary

type: version
unfixedAffected

 

sgx-mpa

package type: binary

type: version
unfixedAffected

 

sgx-pckid-tool

package type: binary

type: version
unfixedAffected

 

tdx-qgs

package type: binary

type: version
unfixedAffected

 

grafana

package type: source

type: version
unfixedAffected

 

nodejs:20::nodejs

package type: source

type: version
unfixedAffected

 

nodejs:22::nodejs

package type: source

type: version
unfixedAffected

 

polkit

package type: source

type: version

tag: rhel-9-including-unpatched:3391f347-998d-8236-1771-5d3de3af53ff

Data Sources

  • RedHat Enterprise Linux CSAF VEX

    redhat-vex

VulsFutureVuls|GitHub Logo IconGitHub