<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T20:09:48.822642+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-20284</id>
    <title>cnvd-2021-20284</title>
    <updated>2026-10-06T20:09:48.890754+00:00</updated>
    <content>cnvd-2021-20284</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-20284"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-42537</id>
    <title>EUVD-2026-42537</title>
    <updated>2026-10-06T20:09:48.890803+00:00</updated>
    <content>EUVD-2026-42537</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-42537"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-14967</id>
    <title>fkie_cve-2020-14967</title>
    <updated>2026-10-06T20:09:48.890818+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An issue was discovered in the jsrsasign package before 8.0.18 for Node.js. Its RSA PKCS1 v1.5 decryption implementation does not detect ciphertext modification by prepending '\0' bytes to ciphertexts (it decrypts modified ciphertexts without error). An attacker might prepend these bytes with the goal of triggering memory corruption issues.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-14967"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xxxq-chmp-67g4</id>
    <title>GHSA-xxxq-chmp-67g4 — RSA PKCS#1 decryption vulnerability with prepending zeros in jsrsasign</title>
    <updated>2026-10-06T20:09:48.890853+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: jsrsasign</p>
<p>### Impact
Jsrsasign supports RSA PKCS#1 v1.5 (i.e. RSAES-PKCS1-v1_5) and RSA-OAEP encryption and decryption. Its encrypted message is represented as BigInteger. When there is a valid encrypted message, a crafted message with prepending zeros can be decrypted by this vulnerability.</p>
<p>- If you don't use RSA PKCS1-v1_5 or RSA-OAEP decryption, this vulnerability is not affected.
- Risk to forge contents of encrypted message is very low.
- Risk to raise memory corruption is low since jsrsasign uses BigInteger class.</p>
<p>### Patches
Users using RSA PKCS1-v1_5 or RSA-OAEP decryption should upgrade to 8.0.18.</p>
<p>### Workarounds
Reject RSA PKCS1-v1_5 or RSA-OAEP encrypted message with unnecessary prepending zeros.</p>
<p>### References
https://nvd.nist.gov/vuln/detail/CVE-2020-14967
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14967
https://vuldb.com/?id.157124
https://kjur.github.io/jsrsasign/api/symbols/KJUR.crypto.Cipher.html#.decrypt
https://github.com/kjur/jsrsasign/issues/439</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xxxq-chmp-67g4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-14967</id>
    <title>gsd-2020-14967</title>
    <updated>2026-10-06T20:09:48.890888+00:00</updated>
    <content>gsd-2020-14967</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-14967"/>
  </entry>
</feed>
