<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T19:23:42.077468+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2021:5171</id>
    <title>ALSA-2021:5171 — Moderate: nodejs:16 security, bug fix, and enhancement update</title>
    <updated>2026-10-03T19:23:42.339782+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: nodejs, AlmaLinux:8: nodejs-devel, AlmaLinux:8: nodejs-docs, AlmaLinux:8: nodejs-full-i18n, AlmaLinux:8: nodejs-nodemon, AlmaLinux:8: nodejs-packaging, AlmaLinux:8: npm</p>
<p>Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.</p>
<p>The following packages have been upgraded to a later upstream version: nodejs (16.13.1), nodejs-nodemon (2.0.15). (BZ#2027610)</p>
<p>Security Fix(es):</p>
<p>* nodejs-json-schema: Prototype pollution vulnerability (CVE-2021-3918)</p>
<p>* nodejs-ini: Prototype pollution via malicious INI file (CVE-2020-7788)</p>
<p>* nodejs-glob-parent: Regular expression denial of service (CVE-2020-28469)</p>
<p>* nodejs-ansi-regex: Regular expression denial of service (ReDoS) matching ANSI escape codes (CVE-2021-3807)</p>
<p>* normalize-url: ReDoS for data URLs (CVE-2021-33502)</p>
<p>* llhttp: HTTP Request Smuggling due to spaces in headers (CVE-2021-22959)</p>
<p>* llhttp: HTTP Request Smuggling when parsing the body of chunked requests (CVE-2021-22960)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2021:5171"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-gulp-2020-28469</id>
    <title>BIT-gulp-2020-28469 — Regular Expression Denial of Service (ReDoS)</title>
    <updated>2026-10-03T19:23:42.339881+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: gulp</p>
<p>This affects the package glob-parent before 5.1.2. The enclosure regex used to check for strings ending in enclosure containing path separator.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-gulp-2020-28469"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2021-avi-791</id>
    <title>certfr-2021-avi-791 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T19:23:42.339905+00:00</updated>
    <content>certfr-2021-avi-791</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2021-avi-791"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-168452</id>
    <title>EUVD-2026-168452</title>
    <updated>2026-10-03T19:23:42.339924+00:00</updated>
    <content>EUVD-2026-168452</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-168452"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-28469</id>
    <title>fkie_cve-2020-28469</title>
    <updated>2026-10-03T19:23:42.339936+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>This affects the package glob-parent before 5.1.2. The enclosure regex used to check for strings ending in enclosure containing path separator.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-28469"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-ww39-953v-wcq6</id>
    <title>GHSA-ww39-953v-wcq6 — glob-parent vulnerable to Regular Expression Denial of Service in enclosure regex</title>
    <updated>2026-10-03T19:23:42.339957+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: glob-parent</p>
<p>This affects the package glob-parent before 5.1.2. The enclosure regex used to check for strings ending in enclosure containing path separator.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-ww39-953v-wcq6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-28469</id>
    <title>gsd-2020-28469</title>
    <updated>2026-10-03T19:23:42.339976+00:00</updated>
    <content>gsd-2020-28469</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-28469"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:1499</id>
    <title>RHSA-2021:1499 — Red Hat Security Advisory: Red Hat Advanced Cluster Management 2.2.3 security and bug fix update</title>
    <updated>2026-10-03T19:23:42.339987+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>nodejs-glob-parent: Regular expression denial of service nodejs-underscore: Arbitrary code execution via the template function nodejs-is-svg: ReDoS via malicious string nodejs-netmask: improper input validation of octal input data nodejs-netmask: incorrectly parses an IP address that has octal integer with invalid character</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:1499"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:5171</id>
    <title>RHSA-2021:5171 — Red Hat Security Advisory: nodejs:16 security, bug fix, and enhancement update</title>
    <updated>2026-10-03T19:23:42.340012+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>nodejs-ini: Prototype pollution via malicious INI file nodejs-glob-parent: Regular expression denial of service nodejs-ansi-regex: Regular expression denial of service (ReDoS) matching ANSI escape codes nodejs-json-schema: Prototype pollution vulnerability llhttp: HTTP Request Smuggling due to spaces in headers llhttp: HTTP Request Smuggling when parsing the body of chunked requests nodejs-normalize-url: ReDoS for data URLs</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:5171"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1354</id>
    <title>WID-SEC-W-2022-1354 — Red Hat Enterprise Linux: Mehrere Schwachstellen</title>
    <updated>2026-10-03T19:23:42.340039+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode auszuführen, Informationen offenzulegen, einen Denial of Service Zustand herbeizuführen, Dateien zu manipulieren oder Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1354"/>
  </entry>
</feed>
