CVE-2026-23950

Aliases:GHSA-r6q2-hw4h-h46wUBUNTU-CVE-2026-23950DEBIAN-CVE-2026-23950CGA-24px-2xrr-m37cCGA-269h-wmc2-vg43CGA-26xq-4c47-8cqpCGA-288p-pj3c-4r82CGA-2h3r-hx66-v6mjCGA-2h57-7pq5-jwvmCGA-3p99-4xj4-8835CGA-3qcg-f627-46w8CGA-3vcm-rf34-7mr2CGA-3w8j-3rwr-2mgrCGA-43r7-g249-v437CGA-455r-h3mg-gpvcCGA-46c8-j35m-c35jCGA-4mvq-4rx5-7587CGA-4qj5-xmvj-m678CGA-4r9f-jmqc-h8gpCGA-58v2-6jgp-v54jCGA-5cgm-7h5r-cgm2CGA-5cvm-9phc-mc4mCGA-5cx6-fm6p-xwvvCGA-5f4v-g8g2-x8c5CGA-5qrc-5mrm-539xCGA-63q2-c8pv-xrrwCGA-65cg-gvhq-65xhCGA-6p8r-x6w4-cqf4CGA-6q5x-q953-9w5wCGA-6qg8-cx9r-93qgCGA-6rfv-8778-m6g4CGA-785m-jcxf-67x3CGA-7rwc-7gw3-mp4jCGA-7xr9-m9mh-x82qCGA-837j-cqgc-m555CGA-866p-vmwx-vxmpCGA-8r59-46xc-wfxvCGA-95f6-c5gc-r8qqCGA-96wp-92gr-58r6CGA-986v-6wgc-w28qCGA-99fq-j3q7-49pvCGA-9hvr-5mp8-w246CGA-ccg8-xvpw-gr3cCGA-cgvm-29hc-5qvxCGA-cv62-wqfm-g8m2CGA-f846-mhrm-95phCGA-ffxg-j66f-8f88CGA-fmg6-h77c-p329CGA-g2f8-8whp-878pCGA-g2gv-xgf9-8x5pCGA-g357-9rrj-gm9vCGA-g8q3-g9jw-g7r3CGA-gfw4-w83v-94gvCGA-hrxq-xfjg-f3w4CGA-jg8h-8w2c-rgg3CGA-jjh2-xp4w-r7ffCGA-jp5q-fvw7-rxwpCGA-m8cc-x477-cmw4CGA-mr76-jgg5-8692CGA-p368-5xpm-g99wCGA-p3x6-p5rr-2x9hCGA-pwp8-4vfh-7q24CGA-pww5-v6q5-gpmpCGA-22hg-5h94-gjc3CGA-25h6-wccw-g5f9CGA-264r-qvxm-wph2CGA-2c9f-8fp4-qx22CGA-2gfc-52g4-2whpCGA-2hfg-39fq-48hvCGA-2jm2-5497-vc4wCGA-2jmm-3346-77frCGA-2ppq-rgrv-j6vgCGA-2w4h-v4vp-jphcCGA-37m4-c2xp-4pcfCGA-3crm-24m7-8fc4CGA-3hjh-v6q8-fjc5CGA-47x8-jhj6-4r3jCGA-4chv-2rpf-9h5qCGA-4mcg-qprp-mhqrCGA-4qjq-78gp-3frhCGA-4wf5-v7hg-vh86CGA-4wjh-h83m-rww7CGA-53ph-hg8r-jwmjCGA-572g-4jwp-6w7pCGA-5cfq-hw57-ccwrCGA-5g2r-8rg2-m85mCGA-5j4q-f8wg-42g8CGA-5m65-6jwq-rmccCGA-5mvq-vxp4-9q9cCGA-5p2h-572m-jmqmCGA-5pq9-56jc-q8j2CGA-5rc4-w964-6vg5CGA-6776-vwgj-2xfhCGA-699p-385w-q9mrCGA-69qj-q56v-m534CGA-69wp-m8qj-3x5rCGA-6f93-jgvj-7j98CGA-6fmw-9pfp-92w5CGA-6fvq-m85p-5qm9CGA-6j2c-fxvg-59f3CGA-6jjh-rhcq-hmjxCGA-745p-668f-f3hjCGA-748r-pjjh-3rpjCGA-7fh4-hp59-rfm4CGA-7gp9-347p-436xCGA-7vv3-xpxc-jmwpCGA-7w93-rhcr-v5cpCGA-7xv2-v3wr-67m7CGA-829w-773h-8ch9CGA-84c7-87xv-9crvCGA-84g5-r89q-3cjgCGA-8563-f249-hjmxCGA-85gc-qfrv-qgv5CGA-86wg-c4cj-q6m2CGA-882m-jmhh-6prjCGA-886q-74c4-64pvCGA-8cr9-g4qr-q66mCGA-8f7x-wx2f-w6x9CGA-8p22-4f4f-wwqrCGA-8ppr-mhrg-gc6mCGA-8vc3-c7rc-cr3pCGA-8w3r-mhcr-44h6CGA-8wq7-gfvg-mc8rCGA-8xw7-4v5x-ff36CGA-9454-qxqj-2cf8CGA-9594-h455-crccCGA-983p-qv8c-5j88CGA-9chj-gpg7-hcj8CGA-9mmm-63px-fwpqCGA-9qmc-q37g-rfr4CGA-c62c-jjvg-jx59CGA-c6jr-9fv8-3q89CGA-c75w-5wvr-323wCGA-c9wf-7hwq-pcmfCGA-cfg3-jhfr-2mhwCGA-cj5r-7v8h-4q2vCGA-cpqg-49jc-q5p4CGA-cv48-rxpq-33q8CGA-cvv9-g5c4-gh9xCGA-f4j7-pphj-qmmhCGA-f99f-h4c3-mqx8CGA-fc5v-36rh-28vvCGA-fcgh-3x46-87f8CGA-fh52-cp3r-wcjfCGA-fj3r-pj8f-fhf9CGA-fq2x-g6fj-v3crCGA-frwj-f32p-8cr6CGA-g557-mwcm-fww9CGA-gc39-7vjq-6426CGA-gcp3-2553-vx93CGA-h269-jmr7-fx9vCGA-h29j-2hgc-rv7qCGA-h4fh-grmg-prp4CGA-h5cm-7pgv-9qrgCGA-h8gp-fm34-cqp2CGA-hc55-jm6w-w36wCGA-hgp5-pcmr-jpvwCGA-hmjg-mhr9-cch2CGA-hp6j-4869-8mrjCGA-hwc2-8gjv-xv2gCGA-hwf9-wf3j-2hmfCGA-j6f9-4jpx-68m7CGA-jcjv-h9g6-x56cCGA-jf9p-q4w8-mrj9CGA-jjp7-xfm5-c2p4CGA-jmw6-cxpx-wrxcCGA-jr59-vhrj-fh87CGA-m78v-jv3g-4h5qCGA-mj68-w4c7-h82jCGA-mmhj-hx69-4285CGA-mp2f-jfgh-3559CGA-mpq9-v9vg-8g3pCGA-mrqc-8gj6-xj94CGA-p6r3-w6rx-rxvgCGA-p83v-gvg3-vrj9CGA-p8h2-7259-8p3cCGA-p9f8-fg48-q89jCGA-p9px-mf59-rf7fCGA-pcf5-6pj6-wfq8CGA-phhh-8jrx-4r2cCGA-phmp-7pvx-9q6xCGA-q7mr-34w9-rpxmCGA-q7qr-g99f-25vvCGA-q7vr-5xm8-v4jwCGA-q9jw-f53j-wf63CGA-qg74-ccqh-jr92CGA-qhjq-p7xv-p5p7CGA-qhmq-gwmc-x792CGA-qhqg-cx28-9959CGA-qj68-wc7m-9vh6CGA-qmwh-346f-w756CGA-qq82-2f66-598mCGA-qv22-927j-pf5vCGA-qv3j-x6m2-6w4mCGA-r2m6-8x4q-9622CGA-r586-j769-jwf5CGA-r6c9-rgg9-c54qCGA-r7gm-xg74-2v8xCGA-r9m9-6q43-9j78CGA-rfc3-3mp8-vqq2CGA-rgg3-8hgw-5vr6CGA-rjmm-hpvf-825pCGA-rmw2-j5pw-77v3CGA-rq5v-8ggg-q7fxCGA-rqrc-656j-88whCGA-rvpm-wgw9-5wghCGA-rx55-wgcj-m8x4CGA-rxwm-r2fq-p432CGA-v246-g3j9-7rm5CGA-v27f-cfqq-5hhpCGA-v4rf-6cpq-wf52CGA-v5ch-vqmm-422fCGA-v62h-4cf9-wx3fCGA-v6qq-j467-27c3CGA-v8x7-cv3x-rhx3CGA-v9hf-jjch-3p7qCGA-vhvh-hhjx-9926CGA-vm39-vw48-wf3vCGA-vphc-cpp5-86p4CGA-vw7f-9w3q-j3gcCGA-w32x-p5x9-j47mCGA-w37p-r7r2-c7wcCGA-w443-j7wp-254wCGA-w4jv-459j-j5h2CGA-w7m2-7q22-5vqmCGA-w9r9-q622-cmj7CGA-wc8f-94v5-62c6CGA-wfpr-32m6-jgh6CGA-wp64-q49w-grw4CGA-wq3m-pqjq-2vmpCGA-wqrr-cwh2-v4c8CGA-wqv8-f6w7-2vxxCGA-wrwr-chpm-6cqfCGA-wwpj-rfcj-mx23CGA-x25c-h3px-qvq9CGA-x2vx-f57h-23p8CGA-x32q-7pxc-6729CGA-x7c4-cf98-gfq2CGA-x7j3-pq7v-5f5xCGA-x84r-35rm-mhp2CGA-xfg4-xpgp-fjx9CGA-xph9-7xrf-5mxmCGA-xqr8-cvwv-58fxCGA-xv8g-v2f6-cmv4CGA-xvh5-rxg3-q2qfCGA-227w-gh3m-5f86CGA-qm7x-mmc5-74rp
Advisory lineage Upstream: 0 Downstream: 4
Modified
Published: 20 Jan 2026, 00:40
Last modified:01 Sept 2026, 12:04

Vulnerability Summary

Overall Risk (default)
medium
45/100
CVSS Score
8.8 HIGH
v3.1 (cve.org)
EPSS Score
0.26% LOW
0% probability +0.25%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

20 Jan 2026, 00:40
Published
Vulnerability first disclosed
01 Sept 2026, 12:04
Last Modified
Vulnerability information updated

Description

node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path-reservations` system. On case-insensitive or normalization-insensitive filesystems (such as macOS APFS, In which it has been tested), the library fails to lock colliding paths (e.g., `ß` and `ss`), allowing them to be processed in parallel. This bypasses the library's internal concurrency safeguards and permits Symlink Poisoning attacks via race conditions. The library uses a `PathReservations` system to ensure that metadata checks and file operations for the same path are serialized. This prevents race conditions where one entry might clobber another concurrently. This is a Race Condition which enables Arbitrary File Overwrite. This vulnerability affects users and systems using node-tar on macOS (APFS/HFS+). Because of using `NFD` Unicode normalization (in which `ß` and `ss` are different), conflicting paths do not have their order properly preserved under filesystems that ignore Unicode normalization (e.g., APFS (in which `ß` causes an inode collision with `ss`)). This enables an attacker to circumvent internal parallelization locks (`PathReservations`) using conflicting filenames within a malicious tar archive. The patch in version 7.5.4 updates `path-reservations.js` to use a normalization form that matches the target filesystem's behavior (e.g., `NFKD`), followed by first `toLocaleLowerCase('en')` and then `toLocaleUpperCase('en')`. As a workaround, users who cannot upgrade promptly, and who are programmatically using `node-tar` to extract arbitrary tarball data should filter out all `SymbolicLink` entries (as npm does) to defend against arbitrary file writes via this file system entry name collision issue.

CVSS Metrics

  • v3.1HIGHScore: 8.8CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:L
  • v3.1MEDIUMScore: 5.9CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS Trends

Current EPSS score: 0.26% Percentile: 18%

Techniques & Countermeasures

  • CWE-176Improper Handling of Unicode Encoding

    The product does not properly handle when an input contains Unicode encoding.

  • CWE-352Cross-Site Request Forgery (CSRF)

    The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

  • CWE-367Time-of-check Time-of-use (TOCTOU) Race Condition

    The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

Affected Systems

  • chainguardactions-runner

    < 2.331.0-r1

  • chainguardcode-server

    < 4.106.3-r4

  • chainguarddrupal-11.3

    < 11.3.13-r3

  • chainguardgitlab-rails-ce-18.1

    < 18.1.6-r31

  • chainguardgitlab-rails-ce-18.10

    all

  • chainguardgitlab-rails-ce-18.11

    < 18.11.6-r12

  • chainguardgitlab-rails-ce-18.5

    all

  • chainguardgitlab-rails-ce-18.6

    all

  • chainguardgitlab-rails-ce-18.7

    all

  • chainguardgitlab-rails-ce-18.8

    all

  • chainguardgitlab-rails-ce-18.9

    all

  • chainguardgitlab-rails-ce-19.0

    < 19.0.4-r10 | < 19.0.3-r1

  • chainguardgitlab-rails-ce-19.1

    < 19.1.2-r8

  • chainguardgitlab-rails-ce-19.2

    < 19.2.2-r2

  • chainguardgitlab-rails-ce-fips-18.1

    < 18.1.6-r15 | < 18.1.6-r61

  • chainguardgitlab-rails-ce-fips-18.10

    all

  • chainguardgitlab-rails-ce-fips-18.11

    all

  • chainguardgitlab-rails-ce-fips-18.5

    all

  • chainguardgitlab-rails-ce-fips-18.6

    all

  • chainguardgitlab-rails-ce-fips-18.7

    all

  • chainguardgitlab-rails-ce-fips-18.8

    all

  • chainguardgitlab-rails-ce-fips-18.9

    all

  • chainguardgitlab-rails-ce-fips-19.0

    < 19.0.4-r7

  • chainguardgitlab-rails-ce-fips-19.1

    < 19.1.1-r1 | < 19.1.2-r9

  • chainguardgitlab-rails-ce-fips-19.2

    < 19.2.1-r4

  • chainguardgraalvm-23-ce-nodejs

    all

  • chainguardgraalvm-24-ce-nodejs

    all

  • chainguardgraalvm-25-ce-nodejs

    < 25.0.2-r1

  • chainguardjupyter-base-notebook

    all

  • chainguardkatib-earlystopping

    < 0.19.0-r31

  • chainguardkatib-suggestion-goptuna-compat

    < 0.19.0-r40

  • chainguardkatib-suggestion-hyperband

    < 0.19.0-r31

  • chainguardkatib-suggestion-hyperopt

    < 0.19.0-r31 | < 0.19.0-r40

  • chainguardkatib-suggestion-nas-darts

    < 0.19.0-r31

  • chainguardkatib-suggestion-nas-enas

    < 0.19.0-r31

  • chainguardkatib-suggestion-optuna-enas

    < 0.19.0-r31

  • chainguardkatib-suggestion-pbt-enas

    < 0.19.0-r31

  • chainguardkatib-suggestion-skopt-enas

    < 0.19.0-r31

  • chainguardkatib-tfevent-metricscollector

    < 0.19.0-r31

  • chainguardkibana-7

    all

  • chainguardkibana-8.17

    < 8.17.10-r8

  • chainguardkibana-8.17-iamguarded

    < 8.17.10-r8

  • chainguardkibana-8.18

    < 8.18.8-r8

  • chainguardkibana-8.18-iamguarded

    < 8.18.8-r8

  • chainguardkibana-8.19

    < 8.19.10-r2

  • chainguardkibana-8.19-iamguarded

    < 8.19.10-r2

  • chainguardkibana-9.0

    < 9.0.8-r8

  • chainguardkibana-9.0-bitnami

    < 9.0.8-r8

  • chainguardkibana-9.0-iamguarded

    < 9.0.8-r8

  • chainguardkibana-9.1

    < 9.1.10-r3

Showing first 50 affected entries in server-rendered view.

References (16)