node-tar has Race Condition in Path Reservations via Unicode Ligature Collisions on macOS APFS
Published Jan 20, 2026
8.8
HIGHCVSS 3.1
EPSS 0.26%
Description
node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path-reservations` system. On case-insensitive or normalization-insensitive filesystems (such as macOS APFS, In which it has been tested), the library fails to lock colliding paths (e.g., `ß` and `ss`), allowing them to be processed in parallel. This bypasses the library's internal concurrency safeguards and permits Symlink Poisoning attacks via race conditions. The library uses a `PathReservations` system to ensure that metadata checks and file operations for the same path are serialized. This prevents race conditions where one entry might clobber another concurrently. This is a Race Condition which enables Arbitrary File Overwrite. This vulnerability affects users and systems using node-tar on macOS (APFS/HFS+). Because of using `NFD` Unicode normalization (in which `ß` and `ss` are different), conflicting paths do not have their order properly preserved under filesystems that ignore Unicode normalization (e.g., APFS (in which `ß` causes an inode collision with `ss`)). This enables an attacker to circumvent internal parallelization locks (`PathReservations`) using conflicting filenames within a malicious tar archive. The patch in version 7.5.4 updates `path-reservations.js` to use a normalization form that matches the target filesystem's behavior (e.g., `NFKD`), followed by first `toLocaleLowerCase('en')` and then `toLocaleUpperCase('en')`. As a workaround, users who cannot upgrade promptly, and who are programmatically using `node-tar` to extract arbitrary tarball data should filter out all `SymbolicLink` entries (as npm does) to defend against arbitrary file writes via this file system entry name collision issue.
Affected products
-
- Version < 7.5.4StatusaffectedConstraints-
- Version
No data.
Red Hat Enterprise Linux 10
linux-sgx-0:2.26-7.el10
Fixed · RHSA-2026:18480
Red Hat Enterprise Linux 9
linux-sgx-0:2.26-7.el9
Fixed · RHSA-2026:18868
Red Hat OpenShift Dev Spaces 3.27
devspaces/udi-rhel9:1774451954
Fixed · RHSA-2026:6192
Red Hat Trusted Artifact Signer 1.2
rhtas/rekor-search-ui-rhel9:1770739056
Fixed · RHSA-2026:2926
Red Hat Trusted Artifact Signer 1.3
rhtas/rekor-search-ui-rhel9:1770107452
Fixed · RHSA-2026:2144
Confidential Compute Attestation
openshift-sandboxed-containers/osc-pccs
Affected
Cryostat 4
io.cryostat-cryostat
Not affected
Logging Subsystem for Red Hat OpenShift
openshift-logging/kibana6-rhel8
Will not fix
Migration Toolkit for Containers
rhmtc/openshift-migration-ui-rhel8
Affected
Multicluster Engine for Kubernetes
multicluster-engine/console-mce-rhel8
Not affected
Multicluster Engine for Kubernetes
multicluster-engine/console-mce-rhel9
Not affected
Network Observability Operator
network-observability/network-observability-console-plugin-rhel9
Affected
Node HealthCheck Operator
workload-availability/node-remediation-console-rhel9
Not affected
OpenShift Lightspeed
openshift-lightspeed/lightspeed-to-dataverse-exporter-rhel9
Will not fix
OpenShift Pipelines
openshift-pipelines/pipelines-console-plugin-rhel8
Will not fix
OpenShift Serverless
openshift-serverless-1/kn-eventing-integrations-transform-jsonata-rhel9
Affected
Red Hat 3scale API Management Platform 2
3scale-amp2/system-rhel7
Will not fix
Red Hat 3scale API Management Platform 2
3scale-amp2/system-rhel8
Will not fix
Red Hat 3scale API Management Platform 2
3scale-amp2/system-rhel9
Will not fix
Red Hat 3scale API Management Platform 2
3scale-amp20/system
Will not fix
Red Hat 3scale API Management Platform 2
3scale-amp21/system
Will not fix
Red Hat 3scale API Management Platform 2
3scale-amp22/system
Will not fix
Red Hat 3scale API Management Platform 2
3scale-amp24/system
Will not fix
Red Hat 3scale API Management Platform 2
3scale-amp25/system
Will not fix
Red Hat 3scale API Management Platform 2
3scale-amp26/system
Will not fix
Red Hat AMQ Broker 7
org.jolokia-jolokia-parent
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/console-rhel9
Not affected
Red Hat Ansible Automation Platform 2
ansible-automation-platform-tech-preview/mcp-server-rhel9
Not affected
Red Hat Connectivity Link 1
rhcl-1/rhcl-console-plugin-rhel9
Affected
Red Hat Developer Hub
rhdh/rhdh-hub-rhel9
Will not fix
Red Hat Enterprise Linux 10
nodejs22
Not affected
Red Hat Enterprise Linux 10
nodejs24
Not affected
Red Hat Enterprise Linux 10
tar
Not affected
Red Hat Enterprise Linux 6
tar
Out of support scope
Red Hat Enterprise Linux 7
tar
Not affected
Red Hat Enterprise Linux 8
grafana
Not affected
Red Hat Enterprise Linux 8
mozjs60
Not affected
Red Hat Enterprise Linux 8
nodejs:20/nodejs
Not affected
Red Hat Enterprise Linux 8
nodejs:22/nodejs
Not affected
Red Hat Enterprise Linux 8
nodejs:24/nodejs
Not affected
Red Hat Enterprise Linux 8
tar
Not affected
Red Hat Enterprise Linux 9
gjs
Not affected
Red Hat Enterprise Linux 9
grafana
Not affected
Red Hat Enterprise Linux 9
nodejs:20/nodejs
Not affected
Red Hat Enterprise Linux 9
nodejs:22/nodejs
Not affected
Red Hat Enterprise Linux 9
nodejs:24/nodejs
Not affected
Red Hat Enterprise Linux 9
polkit
Not affected
Red Hat Enterprise Linux 9
tar
Not affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-cuda-rhel9
Will not fix
Red Hat Fuse 7
io.hawt-project
Will not fix
Red Hat JBoss Enterprise Application Platform 7
io.hawt-project
Not affected
Red Hat JBoss Enterprise Application Platform 8
io.hawt-project
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
io.hawt-project
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-dashboard-rhel8
Affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-dashboard-rhel9
Affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Not affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-console-rhel9
Will not fix
Red Hat OpenShift GitOps
openshift-gitops-1/argocd-rhel8
Will not fix
Red Hat Openshift Data Foundation 4
odf4/mcg-core-rhel9
Affected
Red Hat Openshift Data Foundation 4
odf4/odf-console-rhel9
Affected
Red Hat Process Automation 7
org.uberfire-uberfire-parent
Not affected
Red Hat Quay 3
quay/quay-rhel9
Not affected
Red Hat Satellite 6
satellite/iop-remediations-rhel9
Affected
Red Hat Single Sign-On 7
org.keycloak-keycloak-parent
Not affected
Red Hat build of Apache Camel - HawtIO 4
io.hawt-project
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | linux-sgx-0:2.26-7.el10 | Fixed | RHSA-2026:18480 |
| Red Hat Enterprise Linux 9 | linux-sgx-0:2.26-7.el9 | Fixed | RHSA-2026:18868 |
| Red Hat OpenShift Dev Spaces 3.27 | devspaces/udi-rhel9:1774451954 | Fixed | RHSA-2026:6192 |
| Red Hat Trusted Artifact Signer 1.2 | rhtas/rekor-search-ui-rhel9:1770739056 | Fixed | RHSA-2026:2926 |
| Red Hat Trusted Artifact Signer 1.3 | rhtas/rekor-search-ui-rhel9:1770107452 | Fixed | RHSA-2026:2144 |
| Confidential Compute Attestation | openshift-sandboxed-containers/osc-pccs | Affected | n/a |
| Cryostat 4 | io.cryostat-cryostat | Not affected | n/a |
| Logging Subsystem for Red Hat OpenShift | openshift-logging/kibana6-rhel8 | Will not fix | n/a |
| Migration Toolkit for Containers | rhmtc/openshift-migration-ui-rhel8 | Affected | n/a |
| Multicluster Engine for Kubernetes | multicluster-engine/console-mce-rhel8 | Not affected | n/a |
| Multicluster Engine for Kubernetes | multicluster-engine/console-mce-rhel9 | Not affected | n/a |
| Network Observability Operator | network-observability/network-observability-console-plugin-rhel9 | Affected | n/a |
| Node HealthCheck Operator | workload-availability/node-remediation-console-rhel9 | Not affected | n/a |
| OpenShift Lightspeed | openshift-lightspeed/lightspeed-to-dataverse-exporter-rhel9 | Will not fix | n/a |
| OpenShift Pipelines | openshift-pipelines/pipelines-console-plugin-rhel8 | Will not fix | n/a |
| OpenShift Serverless | openshift-serverless-1/kn-eventing-integrations-transform-jsonata-rhel9 | Affected | n/a |
| Red Hat 3scale API Management Platform 2 | 3scale-amp2/system-rhel7 | Will not fix | n/a |
| Red Hat 3scale API Management Platform 2 | 3scale-amp2/system-rhel8 | Will not fix | n/a |
| Red Hat 3scale API Management Platform 2 | 3scale-amp2/system-rhel9 | Will not fix | n/a |
| Red Hat 3scale API Management Platform 2 | 3scale-amp20/system | Will not fix | n/a |
| Red Hat 3scale API Management Platform 2 | 3scale-amp21/system | Will not fix | n/a |
| Red Hat 3scale API Management Platform 2 | 3scale-amp22/system | Will not fix | n/a |
| Red Hat 3scale API Management Platform 2 | 3scale-amp24/system | Will not fix | n/a |
| Red Hat 3scale API Management Platform 2 | 3scale-amp25/system | Will not fix | n/a |
| Red Hat 3scale API Management Platform 2 | 3scale-amp26/system | Will not fix | n/a |
| Red Hat AMQ Broker 7 | org.jolokia-jolokia-parent | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/console-rhel9 | Not affected | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-tech-preview/mcp-server-rhel9 | Not affected | n/a |
| Red Hat Connectivity Link 1 | rhcl-1/rhcl-console-plugin-rhel9 | Affected | n/a |
| Red Hat Developer Hub | rhdh/rhdh-hub-rhel9 | Will not fix | n/a |
| Red Hat Enterprise Linux 10 | nodejs22 | Not affected | n/a |
| Red Hat Enterprise Linux 10 | nodejs24 | Not affected | n/a |
| Red Hat Enterprise Linux 10 | tar | Not affected | n/a |
| Red Hat Enterprise Linux 6 | tar | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | tar | Not affected | n/a |
| Red Hat Enterprise Linux 8 | grafana | Not affected | n/a |
| Red Hat Enterprise Linux 8 | mozjs60 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | nodejs:20/nodejs | Not affected | n/a |
| Red Hat Enterprise Linux 8 | nodejs:22/nodejs | Not affected | n/a |
| Red Hat Enterprise Linux 8 | nodejs:24/nodejs | Not affected | n/a |
| Red Hat Enterprise Linux 8 | tar | Not affected | n/a |
| Red Hat Enterprise Linux 9 | gjs | Not affected | n/a |
| Red Hat Enterprise Linux 9 | grafana | Not affected | n/a |
| Red Hat Enterprise Linux 9 | nodejs:20/nodejs | Not affected | n/a |
| Red Hat Enterprise Linux 9 | nodejs:22/nodejs | Not affected | n/a |
| Red Hat Enterprise Linux 9 | nodejs:24/nodejs | Not affected | n/a |
| Red Hat Enterprise Linux 9 | polkit | Not affected | n/a |
| Red Hat Enterprise Linux 9 | tar | Not affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-cuda-rhel9 | Will not fix | n/a |
| Red Hat Fuse 7 | io.hawt-project | Will not fix | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | io.hawt-project | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | io.hawt-project | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | io.hawt-project | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-dashboard-rhel8 | Affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-dashboard-rhel9 | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-console-rhel9 | Will not fix | n/a |
| Red Hat OpenShift GitOps | openshift-gitops-1/argocd-rhel8 | Will not fix | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/mcg-core-rhel9 | Affected | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/odf-console-rhel9 | Affected | n/a |
| Red Hat Process Automation 7 | org.uberfire-uberfire-parent | Not affected | n/a |
| Red Hat Quay 3 | quay/quay-rhel9 | Not affected | n/a |
| Red Hat Satellite 6 | satellite/iop-remediations-rhel9 | Affected | n/a |
| Red Hat Single Sign-On 7 | org.keycloak-keycloak-parent | Not affected | n/a |
| Red Hat build of Apache Camel - HawtIO 4 | io.hawt-project | Not affected | n/a |
tar
npm
Introduced 0 Fixed 7.5.4
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | tar | 0 | 7.5.4 |
Remediation
Red Hat statement
This vulnerability is rated Important for Red Hat products. The `node-tar` library is susceptible to a race condition due to incomplete handling of Unicode path collisions, which can lead to arbitrary file overwrites via symlink poisoning. However, this issue primarily affects case-insensitive or normalization-insensitive filesystems. Red Hat Enterprise Linux and other Red Hat products typically utilize case-sensitive filesystems, which may limit the direct impact of this flaw in default configurations.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (13)
- https://access.redhat.com/errata/RHSA-2026:18480
- https://access.redhat.com/errata/RHSA-2026:18868
- https://access.redhat.com/errata/RHSA-2026:2144
- https://access.redhat.com/errata/RHSA-2026:2926
- https://access.redhat.com/errata/RHSA-2026:6192
- https://access.redhat.com/security/cve/CVE-2026-23950 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2431036 Issue Tracking
- https://github.com/advisories/GHSA-r6q2-hw4h-h46w Advisory
- https://github.com/isaacs/node-tar/commit/3b1abfae650056edfabcbe0a0df5954d390521e6 x_refsource_MISCPatch
- https://github.com/isaacs/node-tar/security/advisories/GHSA-r6q2-hw4h-h46w x_refsource_CONFIRMExploitMitigationVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-23950
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23950.json
- https://www.cve.org/CVERecord?id=CVE-2026-23950
Change history (0)
No recorded changes yet.