[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2026-23950":6},{"stargazers_count":4,"fetched_at":5},7,"2026-08-01T00:21:03.480Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":62,"aliases":72,"duplicate_of":9,"upstream":74,"downstream":75,"duplicates":84,"related":85,"reserved_at":9,"published_at":88,"modified_at":89,"state":90,"summary":91,"references_raw":99,"kevs":163,"epss":164,"epss_history":167,"metrics":426,"affected":440},"CVE-2026-23950","node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path-reservations` system. On case-insensitive or normalization-insensitive filesystems (such as macOS APFS, In which it has been tested), the library fails to lock colliding paths (e.g., `ß` and `ss`), allowing them to be processed in parallel. This bypasses the library's internal concurrency safeguards and permits Symlink Poisoning attacks via race conditions. The library uses a `PathReservations` system to ensure that metadata checks and file operations for the same path are serialized. This prevents race conditions where one entry might clobber another concurrently. This is a Race Condition which enables Arbitrary File Overwrite. This vulnerability affects users and systems using node-tar on macOS (APFS/HFS+). Because of using `NFD` Unicode normalization (in which `ß` and `ss` are different), conflicting paths do not have their order properly preserved under filesystems that ignore Unicode normalization (e.g., APFS (in which `ß` causes an inode collision with `ss`)). This enables an attacker to circumvent internal parallelization locks (`PathReservations`) using conflicting filenames within a malicious tar archive. The patch in version 7.5.4 updates `path-reservations.js` to use a normalization form that matches the target filesystem's behavior (e.g., `NFKD`), followed by first `toLocaleLowerCase('en')` and then `toLocaleUpperCase('en')`. As a workaround, users who cannot upgrade promptly, and who are programmatically using `node-tar` to extract arbitrary tarball data should filter out all `SymbolicLink` entries (as npm does) to defend against arbitrary file writes via this file system entry name collision issue.",null,[11,23,47],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":9,"capec":18},"CWE-176","Improper Handling of Unicode Encoding","The product does not properly handle when an input contains Unicode encoding.","weakness","Draft","Variant",[19],{"id":20,"name":21,"techniques":22},"CAPEC-71","Using Unicode Encoding to Bypass Validation Logic",[],{"_key":24,"id":24,"name":25,"description":26,"type":15,"status":27,"abstraction":28,"likelihood_of_exploit":29,"capec":30},"CWE-352","Cross-Site Request Forgery (CSRF)","The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.","Stable","Compound","Medium",[31,35,39,43],{"id":32,"name":33,"techniques":34},"CAPEC-111","JSON Hijacking (aka JavaScript Hijacking)",[],{"id":36,"name":37,"techniques":38},"CAPEC-462","Cross-Domain Search Timing",[],{"id":40,"name":41,"techniques":42},"CAPEC-467","Cross Site Identification",[],{"id":44,"name":45,"techniques":46},"CAPEC-62","Cross Site Request Forgery",[],{"_key":48,"id":48,"name":49,"description":50,"type":15,"status":51,"abstraction":52,"likelihood_of_exploit":29,"capec":53},"CWE-367","Time-of-check Time-of-use (TOCTOU) Race Condition","The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.","Incomplete","Base",[54,58],{"id":55,"name":56,"techniques":57},"CAPEC-27","Leveraging Race Conditions via Symbolic Links",[],{"id":59,"name":60,"techniques":61},"CAPEC-29","Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions",[],[63],{"_key":64,"name":65,"source":66,"url":67,"maturity":68,"reliability_score":69,"verified":70,"type":9,"platforms":71,"requires_auth":9,"exploitdb":9,"metasploit":9},"GITHUB_ISAACS_NODE-TAR","Node Tar","github","https://github.com/isaacs/node-tar/security/advisories/GHSA-f5x3-32g6-xq36","poc",0.3,false,[],[73],"GHSA-r6q2-hw4h-h46w",[],[76,78,80,82],{"_key":77},"DEBIAN-CVE-2026-23950",{"_key":79},"RHSA-2026:18480",{"_key":81},"RHSA-2026:18868",{"_key":83},"UBUNTU-CVE-2026-23950",[],[86],{"_key":87},"CGA-J5R9-CGJP-W62Q","2026-01-20T00:40:48.510Z","2026-07-15T01:17:44.844Z","Analyzed",{"cisa_kev":70,"cisa_ransomware":70,"cisa_vendor":9,"epss_severity":92,"epss_score":93,"severity":94,"severity_score":95,"severity_version":96,"severity_source":97,"severity_vector":98,"severity_status":90},"low",0.00233,"high",8.8,"v3.1","cve.org","CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:L",[100,111,117,122,127,133,138,143,147,151,155,159],{"url":101,"sources":102,"tags":105},"https://github.com/isaacs/node-tar/security/advisories/GHSA-r6q2-hw4h-h46w",[97,103,104],"nvd","osv_npm",[106,107,108,109,110],"X Refsource CONFIRM","WEB","Exploit","Mitigation","Vendor Advisory",{"url":112,"sources":113,"tags":114},"https://github.com/isaacs/node-tar/commit/3b1abfae650056edfabcbe0a0df5954d390521e6",[97,103,104],[115,107,116],"X Refsource MISC","Patch",{"url":118,"sources":119,"tags":120},"https://nvd.nist.gov/vuln/detail/CVE-2026-23950",[104],[121],"Advisory",{"url":123,"sources":124,"tags":125},"https://github.com/isaacs/node-tar",[104],[126],"PACKAGE",{"url":128,"sources":129,"tags":130},"https://access.redhat.com/security/cve/CVE-2026-23950",[97],[131,132],"VDB Entry","X Refsource REDHAT",{"url":134,"sources":135,"tags":136},"https://bugzilla.redhat.com/show_bug.cgi?id=2431036",[97],[137,132],"Issue Tracking",{"url":139,"sources":140,"tags":141},"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23950.json",[97],[142],"X Sadp Csaf Vex",{"url":144,"sources":145,"tags":146},"https://access.redhat.com/errata/RHSA-2026:18480",[97],[110,132],{"url":148,"sources":149,"tags":150},"https://access.redhat.com/errata/RHSA-2026:18868",[97],[110,132],{"url":152,"sources":153,"tags":154},"https://access.redhat.com/errata/RHSA-2026:6192",[97],[110,132],{"url":156,"sources":157,"tags":158},"https://access.redhat.com/errata/RHSA-2026:2926",[97],[110,132],{"url":160,"sources":161,"tags":162},"https://access.redhat.com/errata/RHSA-2026:2144",[97],[110,132],[],{"date":165,"score":93,"percentile":166},"2026-07-05",0.14161,[168,172,175,178,181,184,187,191,194,197,200,203,206,209,212,215,218,221,224,227,230,233,236,239,242,245,248,251,254,257,261,264,267,271,274,277,280,282,285,288,290,293,296,300,303,306,309,311,314,316,319,321,324,326,328,330,333,335,337,339,341,344,347,349,352,355,358,361,364,367,370,373,376,378,381,384,386,388,391,394,397,400,403,406,409,412,415,418,420,423],{"date":169,"score":170,"percentile":171},"2026-01-20",0.00014,0.02057,{"date":173,"score":170,"percentile":174},"2026-01-21",0.02055,{"date":176,"score":170,"percentile":177},"2026-01-22",0.02048,{"date":179,"score":170,"percentile":180},"2026-01-23",0.02059,{"date":182,"score":170,"percentile":183},"2026-01-24",0.02073,{"date":185,"score":170,"percentile":186},"2026-01-25",0.02065,{"date":188,"score":189,"percentile":190},"2026-01-26",0.00015,0.02547,{"date":192,"score":189,"percentile":193},"2026-01-27",0.02548,{"date":195,"score":189,"percentile":196},"2026-01-28",0.02551,{"date":198,"score":189,"percentile":199},"2026-01-29",0.02572,{"date":201,"score":189,"percentile":202},"2026-01-30",0.02583,{"date":204,"score":189,"percentile":205},"2026-01-31",0.02604,{"date":207,"score":189,"percentile":208},"2026-02-01",0.02663,{"date":210,"score":189,"percentile":211},"2026-02-02",0.02659,{"date":213,"score":189,"percentile":214},"2026-02-03",0.02662,{"date":216,"score":189,"percentile":217},"2026-02-04",0.0266,{"date":219,"score":189,"percentile":220},"2026-02-05",0.0268,{"date":222,"score":189,"percentile":223},"2026-02-06",0.02704,{"date":225,"score":189,"percentile":226},"2026-02-07",0.02732,{"date":228,"score":189,"percentile":229},"2026-02-08",0.02731,{"date":231,"score":189,"percentile":232},"2026-02-09",0.027,{"date":234,"score":189,"percentile":235},"2026-02-10",0.02714,{"date":237,"score":189,"percentile":238},"2026-02-11",0.02807,{"date":240,"score":189,"percentile":241},"2026-02-12",0.02848,{"date":243,"score":189,"percentile":244},"2026-02-13",0.02886,{"date":246,"score":189,"percentile":247},"2026-02-14",0.02921,{"date":249,"score":189,"percentile":250},"2026-02-15",0.0292,{"date":252,"score":189,"percentile":253},"2026-02-16",0.02911,{"date":255,"score":189,"percentile":256},"2026-02-17",0.0289,{"date":258,"score":259,"percentile":260},"2026-02-18",0.00005,0.00241,{"date":262,"score":259,"percentile":263},"2026-02-19",0.00251,{"date":265,"score":259,"percentile":266},"2026-02-20",0.00253,{"date":268,"score":269,"percentile":270},"2026-02-21",0.00006,0.00309,{"date":272,"score":269,"percentile":273},"2026-02-22",0.00308,{"date":275,"score":269,"percentile":276},"2026-02-23",0.00306,{"date":278,"score":269,"percentile":279},"2026-02-24",0.00304,{"date":281,"score":269,"percentile":279},"2026-02-25",{"date":283,"score":269,"percentile":284},"2026-02-26",0.00307,{"date":286,"score":269,"percentile":287},"2026-02-27",0.00305,{"date":289,"score":269,"percentile":284},"2026-02-28",{"date":291,"score":269,"percentile":292},"2026-03-01",0.003,{"date":294,"score":269,"percentile":295},"2026-03-02",0.00299,{"date":297,"score":298,"percentile":299},"2026-03-03",0.00008,0.00619,{"date":301,"score":298,"percentile":302},"2026-03-04",0.00628,{"date":304,"score":298,"percentile":305},"2026-03-05",0.00636,{"date":307,"score":298,"percentile":308},"2026-03-06",0.00633,{"date":310,"score":298,"percentile":308},"2026-03-07",{"date":312,"score":298,"percentile":313},"2026-03-08",0.00632,{"date":315,"score":298,"percentile":308},"2026-03-09",{"date":317,"score":298,"percentile":318},"2026-03-10",0.00634,{"date":320,"score":298,"percentile":313},"2026-03-11",{"date":322,"score":298,"percentile":323},"2026-03-12",0.00638,{"date":325,"score":298,"percentile":305},"2026-03-13",{"date":327,"score":298,"percentile":305},"2026-03-14",{"date":329,"score":298,"percentile":318},"2026-03-15",{"date":331,"score":298,"percentile":332},"2026-03-16",0.00631,{"date":334,"score":298,"percentile":313},"2026-03-17",{"date":336,"score":298,"percentile":308},"2026-03-18",{"date":338,"score":298,"percentile":308},"2026-03-19",{"date":340,"score":298,"percentile":308},"2026-03-20",{"date":342,"score":298,"percentile":343},"2026-03-21",0.00682,{"date":345,"score":298,"percentile":346},"2026-03-22",0.0068,{"date":348,"score":298,"percentile":346},"2026-03-23",{"date":350,"score":298,"percentile":351},"2026-03-24",0.00679,{"date":353,"score":298,"percentile":354},"2026-03-25",0.00684,{"date":356,"score":298,"percentile":357},"2026-03-26",0.00683,{"date":359,"score":298,"percentile":360},"2026-03-27",0.00687,{"date":362,"score":298,"percentile":363},"2026-03-28",0.00686,{"date":365,"score":298,"percentile":366},"2026-03-29",0.00671,{"date":368,"score":298,"percentile":369},"2026-03-30",0.00667,{"date":371,"score":298,"percentile":372},"2026-03-31",0.00666,{"date":374,"score":298,"percentile":375},"2026-04-01",0.00663,{"date":377,"score":298,"percentile":369},"2026-04-02",{"date":379,"score":298,"percentile":380},"2026-04-03",0.00659,{"date":382,"score":298,"percentile":383},"2026-04-04",0.0066,{"date":385,"score":298,"percentile":380},"2026-04-05",{"date":387,"score":298,"percentile":383},"2026-04-06",{"date":389,"score":298,"percentile":390},"2026-04-07",0.00662,{"date":392,"score":298,"percentile":393},"2026-04-08",0.00661,{"date":395,"score":298,"percentile":396},"2026-04-09",0.00654,{"date":398,"score":298,"percentile":399},"2026-04-10",0.00656,{"date":401,"score":298,"percentile":402},"2026-04-11",0.00653,{"date":404,"score":298,"percentile":405},"2026-04-12",0.00647,{"date":407,"score":298,"percentile":408},"2026-04-13",0.00648,{"date":410,"score":298,"percentile":411},"2026-04-14",0.00641,{"date":413,"score":298,"percentile":414},"2026-04-15",0.00639,{"date":416,"score":298,"percentile":417},"2026-04-16",0.0064,{"date":419,"score":298,"percentile":417},"2026-04-17",{"date":421,"score":298,"percentile":422},"2026-04-18",0.00645,{"date":424,"score":298,"percentile":425},"2026-04-19",0.00643,[427,431,438],{"source":97,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":428,"cvss_v4_0":9},{"baseScore":95,"baseSeverity":429,"vectorString":98,"impactScore":95,"exploitabilityScore":430},"HIGH",7.2,{"source":103,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":432,"cvss_v4_0":9},{"baseScore":433,"baseSeverity":434,"vectorString":435,"impactScore":436,"exploitabilityScore":437},5.9,"MEDIUM","CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",6,5.6,{"source":104,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":439,"cvss_v4_0":9},{"baseScore":95,"baseSeverity":9,"vectorString":98,"impactScore":95,"exploitabilityScore":430},[441,451,457],{"ecosystem":9,"name":442,"vendor":443,"product":442,"cpe_part":444,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":445},"node-tar","isaacs","a",[446],{"version":447,"is_range":448,"range_type":97,"version_start":9,"version_start_type":9,"version_end":449,"version_end_type":450,"fixed_in":9},"\u003C 7.5.4",true,"7.5.4","excluding",{"ecosystem":9,"name":452,"vendor":443,"product":452,"cpe_part":444,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":453},"tar",[454],{"version":455,"is_range":448,"range_type":456,"version_start":9,"version_start_type":9,"version_end":449,"version_end_type":450,"fixed_in":9},"lt7.5.4","cpe",{"ecosystem":458,"name":452,"vendor":458,"product":452,"cpe_part":9,"purl_type":459,"purl_namespace":9,"purl_name":452,"source":9,"versions":460},"Npm","npm",[461],{"version":462,"is_range":448,"range_type":463,"version_start":9,"version_start_type":9,"version_end":449,"version_end_type":450,"fixed_in":9},"lt7_5_4","semver"]