Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 11

Количество 11

fstec логотип

BDU:2026-01713

8 месяцев назад

Уязвимость библиотеки node-tar программной платформы Node.js, позволяющая нарушителю получить доступ на изменение и запись произвольных файлов

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20260508-80-0019

4 месяца назад

Уязвимость nodejs-tar

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2026-23950

8 месяцев назад

node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path-reservations` system. On case-insensitive or normalization-insensitive filesystems (such as macOS APFS, In which it has been tested), the library fails to lock colliding paths (e.g., `ß` and `ss`), allowing them to be processed in parallel. This bypasses the library's internal concurrency safeguards and permits Symlink Poisoning attacks via race conditions. The library uses a `PathReservations` system to ensure that metadata checks and file operations for the same path are serialized. This prevents race conditions where one entry might clobber another concurrently. This is a Race Condition which enables Arbitrary File Overwrite. This vulnerability affects users and systems using node-tar on macOS (APFS/HFS+). Because of using `NFD` Unicode normalization (in which `ß` and `ss` are different), conflicting ...

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2026-23950

8 месяцев назад

node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path-reservations` system. On case-insensitive or normalization-insensitive filesystems (such as macOS APFS, In which it has been tested), the library fails to lock colliding paths (e.g., `ß` and `ss`), allowing them to be processed in parallel. This bypasses the library's internal concurrency safeguards and permits Symlink Poisoning attacks via race conditions. The library uses a `PathReservations` system to ensure that metadata checks and file operations for the same path are serialized. This prevents race conditions where one entry might clobber another concurrently. This is a Race Condition which enables Arbitrary File Overwrite. This vulnerability affects users and systems using node-tar on macOS (APFS/HFS+). Because of using `NFD` Unicode normalization (in which `ß` and `ss` are different), conflicting ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-23950

8 месяцев назад

node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path-reservations` system. On case-insensitive or normalization-insensitive filesystems (such as macOS APFS, In which it has been tested), the library fails to lock colliding paths (e.g., `ß` and `ss`), allowing them to be processed in parallel. This bypasses the library's internal concurrency safeguards and permits Symlink Poisoning attacks via race conditions. The library uses a `PathReservations` system to ensure that metadata checks and file operations for the same path are serialized. This prevents race conditions where one entry might clobber another concurrently. This is a Race Condition which enables Arbitrary File Overwrite. This vulnerability affects users and systems using node-tar on macOS (APFS/HFS+). Because of using `NFD` Unicode normalization (in which `ß` and `ss` are different), conflicting pat

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2026-23950

8 месяцев назад

node-tar,a Tar for Node.js, has a race condition vulnerability in vers ...

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-r6q2-hw4h-h46w

8 месяцев назад

Race Condition in node-tar Path Reservations via Unicode Ligature Collisions on macOS APFS

CVSS3: 8.8
EPSS: Низкий
rocky логотип

RLSA-2026:18868

4 месяца назад

Important: linux-sgx security update

EPSS: Низкий
rocky логотип

RLSA-2026:18480

4 месяца назад

Important: linux-sgx security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-18868

3 месяца назад

ELSA-2026-18868: linux-sgx security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-18480

2 месяца назад

ELSA-2026-18480: linux-sgx security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-01713

Уязвимость библиотеки node-tar программной платформы Node.js, позволяющая нарушителю получить доступ на изменение и запись произвольных файлов

CVSS3: 8.8
0%
Низкий
8 месяцев назад
redos логотип
ROS-20260508-80-0019

Уязвимость nodejs-tar

CVSS3: 8.8
0%
Низкий
4 месяца назад
ubuntu логотип
CVE-2026-23950

node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path-reservations` system. On case-insensitive or normalization-insensitive filesystems (such as macOS APFS, In which it has been tested), the library fails to lock colliding paths (e.g., `ß` and `ss`), allowing them to be processed in parallel. This bypasses the library's internal concurrency safeguards and permits Symlink Poisoning attacks via race conditions. The library uses a `PathReservations` system to ensure that metadata checks and file operations for the same path are serialized. This prevents race conditions where one entry might clobber another concurrently. This is a Race Condition which enables Arbitrary File Overwrite. This vulnerability affects users and systems using node-tar on macOS (APFS/HFS+). Because of using `NFD` Unicode normalization (in which `ß` and `ss` are different), conflicting ...

CVSS3: 8.8
0%
Низкий
8 месяцев назад
redhat логотип
CVE-2026-23950

node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path-reservations` system. On case-insensitive or normalization-insensitive filesystems (such as macOS APFS, In which it has been tested), the library fails to lock colliding paths (e.g., `ß` and `ss`), allowing them to be processed in parallel. This bypasses the library's internal concurrency safeguards and permits Symlink Poisoning attacks via race conditions. The library uses a `PathReservations` system to ensure that metadata checks and file operations for the same path are serialized. This prevents race conditions where one entry might clobber another concurrently. This is a Race Condition which enables Arbitrary File Overwrite. This vulnerability affects users and systems using node-tar on macOS (APFS/HFS+). Because of using `NFD` Unicode normalization (in which `ß` and `ss` are different), conflicting ...

CVSS3: 8.8
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2026-23950

node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path-reservations` system. On case-insensitive or normalization-insensitive filesystems (such as macOS APFS, In which it has been tested), the library fails to lock colliding paths (e.g., `ß` and `ss`), allowing them to be processed in parallel. This bypasses the library's internal concurrency safeguards and permits Symlink Poisoning attacks via race conditions. The library uses a `PathReservations` system to ensure that metadata checks and file operations for the same path are serialized. This prevents race conditions where one entry might clobber another concurrently. This is a Race Condition which enables Arbitrary File Overwrite. This vulnerability affects users and systems using node-tar on macOS (APFS/HFS+). Because of using `NFD` Unicode normalization (in which `ß` and `ss` are different), conflicting pat

CVSS3: 8.8
0%
Низкий
8 месяцев назад
debian логотип
CVE-2026-23950

node-tar,a Tar for Node.js, has a race condition vulnerability in vers ...

CVSS3: 8.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-r6q2-hw4h-h46w

Race Condition in node-tar Path Reservations via Unicode Ligature Collisions on macOS APFS

CVSS3: 8.8
0%
Низкий
8 месяцев назад
rocky логотип
RLSA-2026:18868

Important: linux-sgx security update

4 месяца назад
rocky логотип
RLSA-2026:18480

Important: linux-sgx security update

4 месяца назад
oracle-oval логотип
ELSA-2026-18868

ELSA-2026-18868: linux-sgx security update (IMPORTANT)

3 месяца назад
oracle-oval логотип
ELSA-2026-18480

ELSA-2026-18480: linux-sgx security update (IMPORTANT)

2 месяца назад

Уязвимостей на страницу