CVE-2026-23950

EUVD-2026-3595
node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path-reservations` system. On case-insensitive or normalization-insensitive filesystems (such as macOS APFS, In which it has been tested), the library fails to lock colliding paths (e.g., `ß` and `ss`), allowing them to be processed in parallel. This bypasses the library's internal concurrency safeguards and permits Symlink Poisoning attacks via race conditions. The library uses a `PathReservations` system to ensure that metadata checks and file operations for the same path are serialized. This prevents race conditions where one entry might clobber another concurrently. This is a Race Condition which enables Arbitrary File Overwrite. This vulnerability affects users and systems using node-tar on macOS (APFS/HFS+). Because of using `NFD` Unicode normalization (in which `ß` and `ss` are different), conflicting paths do not have their order properly preserved under filesystems that ignore Unicode normalization (e.g., APFS (in which `ß` causes an inode collision with `ss`)). This enables an attacker to circumvent internal parallelization locks (`PathReservations`) using conflicting filenames within a malicious tar archive. The patch in version 7.5.4 updates `path-reservations.js` to use a normalization form that matches the target filesystem's behavior (e.g., `NFKD`), followed by first `toLocaleLowerCase('en')` and then `toLocaleUpperCase('en')`. As a workaround, users who cannot upgrade promptly, and who are programmatically using `node-tar` to extract arbitrary tarball data should filter out all `SymbolicLink` entries (as npm does) to defend against arbitrary file writes via this file system entry name collision issue.
TOCTOU
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 14%
Affected Products (NVD)
VendorProductVersion
isaacstar
𝑥
< 7.5.4
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatRed Hat Enterprise Linux 10
0:2.26-7.el10 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9
0:2.26-7.el9 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Dev Spaces 3.27
1774451954 ≤
𝑥
< *
ADP
Red HatRed Hat Trusted Artifact Signer 1.2
1770739056 ≤
𝑥
< *
ADP
Red HatRed Hat Trusted Artifact Signer 1.3
1770107452 ≤
𝑥
< *
ADP
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
sgx-common
RHEL 9
0:2.26-7.el9
fixed
sgx-libs
RHEL 9
0:2.26-7.el9
fixed
sgx-mpa
RHEL 9
0:2.26-7.el9
fixed
sgx-pccs
RHEL 9
0:2.26-7.el9
fixed
sgx-pccs-admin
RHEL 9
0:2.26-7.el9
fixed
sgx-pckid-tool
RHEL 9
0:2.26-7.el9
fixed
tdx-qgs
RHEL 9
0:2.26-7.el9
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
nodejs20
Amazon Linux 2023
1:20.20.0-1.amzn2023.0.2
fixed
nodejs20-debuginfo
Amazon Linux 2023
1:20.20.0-1.amzn2023.0.2
fixed
nodejs20-debugsource
Amazon Linux 2023
1:20.20.0-1.amzn2023.0.2
fixed
nodejs20-devel
Amazon Linux 2023
1:20.20.0-1.amzn2023.0.2
fixed
nodejs20-docs
Amazon Linux 2023
1:20.20.0-1.amzn2023.0.2
fixed
nodejs20-full-i18n
Amazon Linux 2023
1:20.20.0-1.amzn2023.0.2
fixed
nodejs20-libs
Amazon Linux 2023
1:20.20.0-1.amzn2023.0.2
fixed
nodejs20-libs-debuginfo
Amazon Linux 2023
1:20.20.0-1.amzn2023.0.2
fixed
nodejs20-npm
Amazon Linux 2023
1:10.8.2-1.20.20.0.1.amzn2023.0.2
fixed
nodejs22
Amazon Linux 2023
1:22.22.0-1.amzn2023.0.2
fixed
nodejs22-debuginfo
Amazon Linux 2023
1:22.22.0-1.amzn2023.0.2
fixed
nodejs22-debugsource
Amazon Linux 2023
1:22.22.0-1.amzn2023.0.2
fixed
nodejs22-devel
Amazon Linux 2023
1:22.22.0-1.amzn2023.0.2
fixed
nodejs22-docs
Amazon Linux 2023
1:22.22.0-1.amzn2023.0.2
fixed
nodejs22-full-i18n
Amazon Linux 2023
1:22.22.0-1.amzn2023.0.2
fixed
nodejs22-libs
Amazon Linux 2023
1:22.22.0-1.amzn2023.0.2
fixed
nodejs22-libs-debuginfo
Amazon Linux 2023
1:22.22.0-1.amzn2023.0.2
fixed
nodejs22-npm
Amazon Linux 2023
1:10.9.4-1.22.22.0.1.amzn2023.0.2
fixed
nodejs24
Amazon Linux 2023
1:24.14.0-1.amzn2023.0.1
fixed
nodejs24-debuginfo
Amazon Linux 2023
1:24.14.0-1.amzn2023.0.1
fixed
nodejs24-debugsource
Amazon Linux 2023
1:24.14.0-1.amzn2023.0.1
fixed
nodejs24-devel
Amazon Linux 2023
1:24.14.0-1.amzn2023.0.1
fixed
nodejs24-docs
Amazon Linux 2023
1:24.14.0-1.amzn2023.0.1
fixed
nodejs24-full-i18n
Amazon Linux 2023
1:24.14.0-1.amzn2023.0.1
fixed
nodejs24-libs
Amazon Linux 2023
1:24.14.0-1.amzn2023.0.1
fixed
nodejs24-libs-debuginfo
Amazon Linux 2023
1:24.14.0-1.amzn2023.0.1
fixed
nodejs24-npm
Amazon Linux 2023
1:11.9.0-1.24.14.0.1.amzn2023.0.1
fixed
v8-11.3-devel
Amazon Linux 2023
3:11.3.244.8-1.20.20.0.1.amzn2023.0.2
fixed
v8-12.4-devel
Amazon Linux 2023
3:12.4.254.21-1.22.22.0.1.amzn2023.0.2
fixed
v8-13.6-devel
Amazon Linux 2023
3:13.6.233.17-1.24.14.0.1.amzn2023.0.1
fixed