<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T15:36:46.922409+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0428</id>
    <title>certfr-2023-avi-0428 — De multiples vulnérabilités ont été découvertes dans les produits &lt;span
class="textit"&gt;Splunk&lt;/span&gt;. Certaines d'entre…</title>
    <updated>2026-10-02T15:36:46.950672+00:00</updated>
    <content>certfr-2023-avi-0428</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0428"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-38875</id>
    <title>cnvd-2020-38875</title>
    <updated>2026-10-02T15:36:46.950723+00:00</updated>
    <content>cnvd-2020-38875</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-38875"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-38075</id>
    <title>EUVD-2026-38075</title>
    <updated>2026-10-02T15:36:46.950739+00:00</updated>
    <content>EUVD-2026-38075</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-38075"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-7662</id>
    <title>fkie_cve-2020-7662</title>
    <updated>2026-10-02T15:36:46.950751+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>websocket-extensions npm module prior to 0.1.4 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be abused by an attacker to conduct Regex Denial Of Service (ReDoS) on a single-threaded server by providing a malicious payload with the Sec-WebSocket-Extensions header.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-7662"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g78m-2chm-r7qv</id>
    <title>GHSA-g78m-2chm-r7qv — Regular Expression Denial of Service in websocket-extensions (NPM package)</title>
    <updated>2026-10-02T15:36:46.950781+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: websocket-extensions</p>
<p>### Impact</p>
<p>The ReDoS flaw allows an attacker to exhaust the server's capacity to process
incoming requests by sending a WebSocket handshake request containing a header
of the following form:</p>
<p>Sec-WebSocket-Extensions: a; b="\c\c\c\c\c\c\c\c\c\c ...</p>
<p>That is, a header containing an unclosed string parameter value whose content is
a repeating two-byte sequence of a backslash and some other character. The
parser takes exponential time to reject this header as invalid, and this will
block the processing of any other work on the same thread. Thus if you are
running a single-threaded server, such a request can render your service
completely unavailable.</p>
<p>### Patches</p>
<p>Users should upgrade to version 0.1.4.</p>
<p>### Workarounds</p>
<p>There are no known work-arounds other than disabling any public-facing
WebSocket functionality you are operating.</p>
<p>### References</p>
<p>- https://blog.jcoglan.com/2020/06/02/redos-vulnerability-in-websocket-extensions/</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g78m-2chm-r7qv"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-7662</id>
    <title>gsd-2020-7662</title>
    <updated>2026-10-02T15:36:46.950816+00:00</updated>
    <content>gsd-2020-7662</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-7662"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2020:2796</id>
    <title>RHSA-2020:2796 — Red Hat Security Advisory: Red Hat OpenShift Service Mesh servicemesh-grafana security update</title>
    <updated>2026-10-02T15:36:46.950828+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kubernetes: YAML parsing vulnerable to "Billion Laughs" attack, allowing for remote denial of service npm-serialize-javascript: XSS via unsafe characters in serialized regular expressions npm-serialize-javascript: allows remote attackers to inject arbitrary code via the function deleteFunctions within index.js npmjs-websocket-extensions: ReDoS vulnerability in Sec-WebSocket-Extensions parser grafana: XSS annotation popup vulnerability grafana: XSS via column.title or cellLinkTooltip grafana: SSRF incorrect access control vulnerability allows unauthenticated users to make grafana send HTTP requests to any URL grafana: XSS via the OpenTSDB datasource</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2020:2796"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1350</id>
    <title>WID-SEC-W-2023-1350 — Splunk Splunk Enterprise: Mehrere Schwachstellen in Komponenten von Drittanbietern</title>
    <updated>2026-10-02T15:36:46.950858+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Splunk Splunk Enterprise in diversen Komponenten von Drittanbietern ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1350"/>
  </entry>
</feed>
