<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T10:44:57.351942+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-02871</id>
    <title>bdu:2021-02871</title>
    <updated>2026-10-04T10:44:57.502940+00:00</updated>
    <content>bdu:2021-02871</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-02871"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2020-avi-757</id>
    <title>certfr-2020-avi-757 — De multiples vulnérabilités ont été découvertes dans IBM Db2. Elles
permettent à un attaquant de provoquer un déni de s…</title>
    <updated>2026-10-04T10:44:57.502981+00:00</updated>
    <content>certfr-2020-avi-757</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2020-avi-757"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-42718</id>
    <title>EUVD-2026-42718</title>
    <updated>2026-10-04T10:44:57.503000+00:00</updated>
    <content>EUVD-2026-42718</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-42718"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-15168</id>
    <title>fkie_cve-2020-15168</title>
    <updated>2026-10-04T10:44:57.503013+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>node-fetch before versions 2.6.1 and 3.0.0-beta.9 did not honor the size option after following a redirect, which means that when a content size was over the limit, a FetchError would never get thrown and the process would end without failure. For most people, this fix will have a little or no impact. However, if you are relying on node-fetch to gate files above a size, the impact could be significant, for example: If you don't double-check the size of the data after fetch() has completed, your JS thread could get tied up doing work on a large file (DoS) and/or cost you money in computing.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-15168"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-w7rc-rwvf-8q5r</id>
    <title>GHSA-w7rc-rwvf-8q5r — The `size` option isn't honored after following a redirect in node-fetch</title>
    <updated>2026-10-04T10:44:57.503045+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: node-fetch</p>
<p>### Impact
Node Fetch did not honor the `size` option after following a redirect, which means that when a content size was over the limit, a `FetchError` would never get thrown and the process would end without failure.</p>
<p>For most people, this fix will have a little or no impact. However, if you are relying on node-fetch to gate files above a size, the impact could be significant, for example: If you don't double-check the size of the data after `fetch()` has completed, your JS thread could get tied up doing work on a large file (DoS) and/or cost you money in computing.</p>
<p>### Patches
We released patched versions for both stable and beta channels:</p>
<p>- For `v2`: 2.6.1
- For `v3`: 3.0.0-beta.9</p>
<p>### Workarounds
None, it is strongly recommended to update as soon as possible.</p>
<p>### For more information
If you have any questions or comments about this advisory:
* Open an issue in [node-fetch](https://github.com/node-fetch/node-fetch/issues/new?assignees=&amp;labels=question&amp;template=support-or-usage.md&amp;title=Question%3A+)
* Contact one of the core maintainers.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-w7rc-rwvf-8q5r"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-15168</id>
    <title>gsd-2020-15168</title>
    <updated>2026-10-04T10:44:57.503081+00:00</updated>
    <content>gsd-2020-15168</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-15168"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhea-2021:0729</id>
    <title>RHEA-2021:0729 — Red Hat Enhancement Advisory: Red Hat Advanced Cluster Management for Kubernetes version 2.2 images</title>
    <updated>2026-10-04T10:44:57.503093+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang-github-buger-jsonparser: infinite loop via a Delete call node-fetch: size of data after fetch() JS thread leads to DoS helm: Chart.yaml is not properly sanitized lead to injection of unwanted information into chart helm: write access to the index file allows an attacker to inject  bad chart into  repository helm: plugin names are not sanitized properly helm: write access to the git repository or plugin archive causing causing a local execution attack jsonparser: GET call can lead to a slice bounds out of range redisgraph: NULL pointer dereference because it mishandles an unquoted string</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhea-2021:0729"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2020:3235-1</id>
    <title>SUSE-SU-2020:3235-1 — Security update for SUSE Manager Server 4.1</title>
    <updated>2026-10-04T10:44:57.503124+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for SUSE Manager Server 4.1</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2020:3235-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-15168</id>
    <title>UBUNTU-CVE-2020-15168</title>
    <updated>2026-10-04T10:44:57.503141+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:18.04:LTS: node-fetch, Ubuntu:20.04:LTS: node-fetch</p>
<p>node-fetch before versions 2.6.1 and 3.0.0-beta.9 did not honor the size option after following a redirect, which means that when a content size was over the limit, a FetchError would never get thrown and the process would end without failure. For most people, this fix will have a little or no impact. However, if you are relying on node-fetch to gate files above a size, the impact could be significant, for example: If you don't double-check the size of the data after fetch() has completed, your JS thread could get tied up doing work on a large file (DoS) and/or cost you money in computing.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-15168"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1603</id>
    <title>WID-SEC-W-2022-1603 — IBM Tivoli Netcool/OMNIbus: Mehrere Schwachstellen</title>
    <updated>2026-10-04T10:44:57.503165+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM Tivoli Netcool/OMNIbus ausnutzen, um beliebigen Programmcode auszuführen, Informationen offenzulegen, Dateien zu manipulieren oder einen Denial of Service Zustand herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1603"/>
  </entry>
</feed>
