<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:20:39.074835+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-181182</id>
    <title>EUVD-2026-181182</title>
    <updated>2026-10-02T19:20:39.082146+00:00</updated>
    <content>EUVD-2026-181182</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-181182"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2018-3750</id>
    <title>fkie_cve-2018-3750</title>
    <updated>2026-10-02T19:20:39.082179+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The utilities function in all versions &lt;= 0.5.0 of the deep-extend node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2018-3750"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hr2v-3952-633q</id>
    <title>GHSA-hr2v-3952-633q — Prototype Pollution in deep-extend</title>
    <updated>2026-10-02T19:20:39.082211+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: deep-extend</p>
<p>Versions of `deep-extend` before 0.5.1 are vulnerable to prototype pollution.</p>
<p>## Recommendation</p>
<p>Update to version 0.5.1 or later.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hr2v-3952-633q"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2018-3750</id>
    <title>gsd-2018-3750</title>
    <updated>2026-10-02T19:20:39.082235+00:00</updated>
    <content>gsd-2018-3750</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2018-3750"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2020:2625</id>
    <title>RHSA-2020:2625 — Red Hat Security Advisory: rh-nodejs8-nodejs security update</title>
    <updated>2026-10-02T19:20:39.082247+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>nodejs-brace-expansion: Regular expression denial of service nodejs-chownr: TOCTOU vulnerability in `chownr` function in chownr.js nodejs-sshpk: ReDoS when parsing crafted invalid public keys in lib/formats/ssh.js nodejs-deep-extend: Prototype pollution can allow attackers to modify object properties npm: Symlink reference outside of node_modules folder through the bin field upon installation npm: Arbitrary file write via constructed entry in the package.json bin field npm: Global node_modules Binary Overwrite</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2020:2625"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:0549</id>
    <title>RHSA-2021:0549 — Red Hat Security Advisory: nodejs:12 security update</title>
    <updated>2026-10-02T19:20:39.082272+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>nodejs-deep-extend: Prototype pollution can allow attackers to modify object properties nodejs-mixin-deep: prototype pollution in function mixin-deep nodejs-set-value: prototype pollution in function set-value nodejs-npm-user-validate: improper input validation when validating user emails leads to ReDoS nodejs-ini: Prototype pollution via malicious INI file nodejs: use-after-free in the TLS implementation nodejs: HTTP request smuggling via two copies of a header field in an http request</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:0549"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-3750</id>
    <title>UBUNTU-CVE-2018-3750</title>
    <updated>2026-10-02T19:20:39.082294+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: node-deep-extend</p>
<p>The utilities function in all versions &lt;= 0.5.0 of the deep-extend node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-3750"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2183</id>
    <title>WID-SEC-W-2026-2183 — Red Hat Software Collections: Mehrere Schwachstellen</title>
    <updated>2026-10-02T19:20:39.082313+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Software Collections ausnutzen, um die Vertraulichkeit, Verfügbarkeit und die Integrität der Anwendungen zu gefährden.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2183"/>
  </entry>
</feed>
