Known Vulnerabilities for Node-tar by Isaacs
Listed below are 10 of the newest known vulnerabilities associated with "Node-tar" by "Isaacs".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-68771 json | ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated ... | Not Provided | 2026-07-31 | 2026-07-31 |
| CVE-2026-68563 json | A flaw was found in ansible-collection-redhat-leapp. When a remediation task is executed with elevated privileges and the `le... | Not Provided | 2026-07-30 | 2026-07-31 |
| CVE-2026-68562 json | A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to a managed node's Leapp repor... | Not Provided | 2026-07-30 | 2026-07-31 |
| CVE-2026-68499 json | re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2's String.prototype.match imple... | Not Provided | 2026-07-30 | 2026-07-31 |
| CVE-2026-67550 json | re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2 validates lastIndex against th... | Not Provided | 2026-07-30 | 2026-07-31 |
| CVE-2026-67320 json | axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy. axios hardens m... | Not Provided | 2026-08-01 | 2026-08-01 |
| CVE-2026-67318 json | axios versions >=1.13.0 (Node.js HTTP adapter) fail to enforce the configured maxBodyLength limit on streamed request bodies ... | Not Provided | 2026-08-01 | 2026-08-01 |
| CVE-2026-67173 json | Pivotick did not validate the URL scheme of node imagePath values derived from graph data before assigning them to SVG image ... | Not Provided | 2026-07-28 | 2026-07-28 |
| CVE-2026-66922 json | Pivotick used plain JavaScript objects as lookup tables indexed by caller-controlled graph node identifiers in its tree-layou... | Not Provided | 2026-07-28 | 2026-07-28 |
| CVE-2026-66921 json | Pivotick’s Markdown node-reference renderer failed to HTML-escape the attacker-controlled nodeName value before interpolati... | Not Provided | 2026-07-28 | 2026-07-28 |