THREAT OPS › Threat News › [NVD] CVE-2026-23950 (HIGH 8.8) — node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path-reservations` system. On case-insensitive or normalization-insensitive filesystems (such as macOS AP
[NVD] CVE-2026-23950 (HIGH 8.8) — node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path-reservations` system. On case-insensitive or normalization-insensitive filesystems (such as macOS AP
CVE-2026-23950 CVSS: 8.8 HIGH Published: 2026-01-20T01:15:57.870
node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path-reservations` system. On case-insensitive or normalization-insensitive filesystems (such as macOS APFS, In which it has been tested), the library fails to
Indicators of compromise
- CVE-2026-23950cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-23950