CVE-2026-23950 is a race condition in node-tar, the tar archive library for Node.js, affecting versions up to and including 7.5.3. Its PathReservations system incompletely handles Unicode path collisions on case-insensitive or normalization-insensitive filesystems, including macOS APFS and HFS+. Paths treated as distinct by the library's NFD normalization can resolve to the same filesystem entry, allowing conflicting archive entries to be processed concurrently instead of serializing their metadata checks and file operations. A malicious archive can bypass these concurrency safeguards to enable symlink poisoning and arbitrary file overwrite.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository is a Node.js proof-of-concept for CVE-2026-23950 affecting the npm `tar` package (pinned to 7.5.3). The core exploit logic is in `index.js`, which constructs an in-memory tar archive using `tar.Header` and a `PassThrough` stream, containing two filenames designed to collide under Unicode normalization/case-insensitive comparisons: `collision_ss` and `collision_ß`. It then extracts the stream with `tar.Unpack({ cwd: 'race_exploit_dir', jobs: 8 })` to encourage parallel extraction and a race window. After extraction, it enumerates files in the target directory, prints inode numbers and content prefixes, and flags success if only one file exists or if two filenames map to the same inode (indicating a collision/overwrite). Supporting files include `package.json`/`package-lock.json` (dependency pinning) and a sample artifact under `race_exploit_dir/`. No network exploitation is performed; impact is local file corruption/overwrite during archive extraction.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A race condition in node-tar allows malicious tar archives containing colliding Unicode filenames to bypass path-reservation locks on case-insensitive or normalization-insensitive filesystems, including macOS APFS/HFS+. Concurrent extraction can enable symlink poisoning and arbitrary file overwrite. The reference assigns a CVSS v3 score of 5.9 and reports exploit availability. Upstream version 7.5.4 fixes path normalization; the listed Echo package update is 6.2.1+ds1+~cs6.1.13-7 or later. Users unable to upgrade can filter out all SymbolicLink entries when extracting untrusted archives.
Path traversal leading to arbitrary write in the node-tar dependency affecting Confluence Data Center.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.