Race condition in node-tar - CVE-2026-23950

 

Race condition in node-tar - CVE-2026-23950

Published: January 20, 2026


Vulnerability identifier: #VU121671
CSH Severity: Medium
CVSS v4: 5.9 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-23950
CWE-ID: CWE-362
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to a race condition in Path Reservations via Unicode Sharp-S (ß) Collisions on macOS APFS. A remote attacker can trick the victim into using a specially crafted archive to bypass the library's internal concurrency safeguards and perform Symlink Poisoning attacks.


Affected software

node-tar
Voice Gateway
IBM Watson Discovery for IBM Cloud Pak for Data
Jira Service Management Data Center
Confluence Data Center
Jira Software Data Center
AppDynamics NodeJS Agent
watsonx Code Assistant On Prem
Maximo Application Suite - Visual Inspection Component
Maximo Application Suite Ai Service
Fedora
linux-sgx
IBM QRadar Data Synchronization App

How to mitigate CVE-2026-23950

Install updates from vendor's website.

node-tar - update to 7.5.4
Voice Gateway - addressed in versions 1.0.8.17, 1.0.8.18, 1.0.8.24, 1.0.8.29
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.1
watsonx Code Assistant On Prem - update to 5.3.1
Jira Service Management Data Center - addressed in versions 10.3.18, 11.3.3
Maximo Application Suite - Visual Inspection Component - addressed in versions 8.9.20, 9.0.17, 9.1.10
Confluence Data Center - addressed in versions 9.2.19, 10.2.10
Maximo Application Suite Ai Service - update to 9.1.13
Jira Software Data Center - addressed in versions 10.3.18, 11.3.3
AppDynamics NodeJS Agent - update to 25.12.1
linux-sgx - update to 2.26-34.fc43
IBM QRadar Data Synchronization App - update to 4.0.0

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins