Skip to content

CVE-2026-59873: Critical tar@7.5.16 DoS vulnerability in published Docker image #1872

Description

@masterofninja

Summary
The published banmanagement/webui:latest Docker image contains a critical vulnerability in the tar package (v7.5.16) that allows denial of service attacks.

Vulnerability Details
CVE ID: CVE-2026-59873
Package: tar
Affected Version: 7.5.16 (and earlier)
Fixed Version: 7.5.19
CVSS Score: 9.2 (Critical)
Impact: Allocation of Resources Without Limits or Throttling
Description
An attacker can provide a malicious tar file that causes excessive resource consumption, crashing the Node.js process and denying service to legitimate users.

Recommendation
Update the tar package to version 7.5.19 or later in package.json or package-lock.json, rebuild the Docker image, and republish to Docker Hub.

How to Reproduce
Run Docker Scout on the published image:

docker scout cves banmanagement/webui:latest --only-severity critical

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions