Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
CVE-2026-23745: According to upstream [1], this is not exploitable in npm. CVE-2026-23950: This is only applicable to case-insensitive or normalization-insensitive filesystems; not generally applicable on Linux. [1]: https://github.com/npm/cli/issues/8917#issuecomment-3775056124