Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 10

Количество 10

fstec логотип

BDU:2026-01713

6 месяцев назад

Уязвимость библиотеки node-tar программной платформы Node.js, позволяющая нарушителю получить доступ на изменение и запись произвольных файлов

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2026-23950

6 месяцев назад

node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path-reservations` system. On case-insensitive or normalization-insensitive filesystems (such as macOS APFS, In which it has been tested), the library fails to lock colliding paths (e.g., `ß` and `ss`), allowing them to be processed in parallel. This bypasses the library's internal concurrency safeguards and permits Symlink Poisoning attacks via race conditions. The library uses a `PathReservations` system to ensure that metadata checks and file operations for the same path are serialized. This prevents race conditions where one entry might clobber another concurrently. This is a Race Condition which enables Arbitrary File Overwrite. This vulnerability affects users and systems using node-tar on macOS (APFS/HFS+). Because of using `NFD` Unicode normalization (in which `ß` and `ss` are different), conflicting ...

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2026-23950

6 месяцев назад

node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path-reservations` system. On case-insensitive or normalization-insensitive filesystems (such as macOS APFS, In which it has been tested), the library fails to lock colliding paths (e.g., `ß` and `ss`), allowing them to be processed in parallel. This bypasses the library's internal concurrency safeguards and permits Symlink Poisoning attacks via race conditions. The library uses a `PathReservations` system to ensure that metadata checks and file operations for the same path are serialized. This prevents race conditions where one entry might clobber another concurrently. This is a Race Condition which enables Arbitrary File Overwrite. This vulnerability affects users and systems using node-tar on macOS (APFS/HFS+). Because of using `NFD` Unicode normalization (in which `ß` and `ss` are different), conflicting ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-23950

6 месяцев назад

node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path-reservations` system. On case-insensitive or normalization-insensitive filesystems (such as macOS APFS, In which it has been tested), the library fails to lock colliding paths (e.g., `ß` and `ss`), allowing them to be processed in parallel. This bypasses the library's internal concurrency safeguards and permits Symlink Poisoning attacks via race conditions. The library uses a `PathReservations` system to ensure that metadata checks and file operations for the same path are serialized. This prevents race conditions where one entry might clobber another concurrently. This is a Race Condition which enables Arbitrary File Overwrite. This vulnerability affects users and systems using node-tar on macOS (APFS/HFS+). Because of using `NFD` Unicode normalization (in which `ß` and `ss` are different), conflicting pat

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2026-23950

6 месяцев назад

node-tar,a Tar for Node.js, has a race condition vulnerability in vers ...

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-r6q2-hw4h-h46w

6 месяцев назад

Race Condition in node-tar Path Reservations via Unicode Ligature Collisions on macOS APFS

CVSS3: 8.8
EPSS: Низкий
rocky логотип

RLSA-2026:18868

2 месяца назад

Important: linux-sgx security update

EPSS: Низкий
rocky логотип

RLSA-2026:18480

2 месяца назад

Important: linux-sgx security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-18868

около 2 месяцев назад

ELSA-2026-18868: linux-sgx security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-18480

24 дня назад

ELSA-2026-18480: linux-sgx security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-01713

Уязвимость библиотеки node-tar программной платформы Node.js, позволяющая нарушителю получить доступ на изменение и запись произвольных файлов

CVSS3: 8.8
0%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2026-23950

node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path-reservations` system. On case-insensitive or normalization-insensitive filesystems (such as macOS APFS, In which it has been tested), the library fails to lock colliding paths (e.g., `ß` and `ss`), allowing them to be processed in parallel. This bypasses the library's internal concurrency safeguards and permits Symlink Poisoning attacks via race conditions. The library uses a `PathReservations` system to ensure that metadata checks and file operations for the same path are serialized. This prevents race conditions where one entry might clobber another concurrently. This is a Race Condition which enables Arbitrary File Overwrite. This vulnerability affects users and systems using node-tar on macOS (APFS/HFS+). Because of using `NFD` Unicode normalization (in which `ß` and `ss` are different), conflicting ...

CVSS3: 8.8
0%
Низкий
6 месяцев назад
redhat логотип
CVE-2026-23950

node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path-reservations` system. On case-insensitive or normalization-insensitive filesystems (such as macOS APFS, In which it has been tested), the library fails to lock colliding paths (e.g., `ß` and `ss`), allowing them to be processed in parallel. This bypasses the library's internal concurrency safeguards and permits Symlink Poisoning attacks via race conditions. The library uses a `PathReservations` system to ensure that metadata checks and file operations for the same path are serialized. This prevents race conditions where one entry might clobber another concurrently. This is a Race Condition which enables Arbitrary File Overwrite. This vulnerability affects users and systems using node-tar on macOS (APFS/HFS+). Because of using `NFD` Unicode normalization (in which `ß` and `ss` are different), conflicting ...

CVSS3: 8.8
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2026-23950

node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path-reservations` system. On case-insensitive or normalization-insensitive filesystems (such as macOS APFS, In which it has been tested), the library fails to lock colliding paths (e.g., `ß` and `ss`), allowing them to be processed in parallel. This bypasses the library's internal concurrency safeguards and permits Symlink Poisoning attacks via race conditions. The library uses a `PathReservations` system to ensure that metadata checks and file operations for the same path are serialized. This prevents race conditions where one entry might clobber another concurrently. This is a Race Condition which enables Arbitrary File Overwrite. This vulnerability affects users and systems using node-tar on macOS (APFS/HFS+). Because of using `NFD` Unicode normalization (in which `ß` and `ss` are different), conflicting pat

CVSS3: 8.8
0%
Низкий
6 месяцев назад
debian логотип
CVE-2026-23950

node-tar,a Tar for Node.js, has a race condition vulnerability in vers ...

CVSS3: 8.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-r6q2-hw4h-h46w

Race Condition in node-tar Path Reservations via Unicode Ligature Collisions on macOS APFS

CVSS3: 8.8
0%
Низкий
6 месяцев назад
rocky логотип
RLSA-2026:18868

Important: linux-sgx security update

2 месяца назад
rocky логотип
RLSA-2026:18480

Important: linux-sgx security update

2 месяца назад
oracle-oval логотип
ELSA-2026-18868

ELSA-2026-18868: linux-sgx security update (IMPORTANT)

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-18480

ELSA-2026-18480: linux-sgx security update (IMPORTANT)

24 дня назад

Уязвимостей на страницу