<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T20:14:32.911005+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2021:0548</id>
    <title>ALSA-2021:0548 — Moderate: nodejs:10 security update</title>
    <updated>2026-10-02T20:14:33.068851+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: nodejs-nodemon, AlmaLinux:8: nodejs-packaging</p>
<p>Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.</p>
<p>The following packages have been upgraded to a later upstream version: nodejs (10.23.1).</p>
<p>Security Fix(es):</p>
<p>* libuv: buffer overflow in realpath (CVE-2020-8252)</p>
<p>* nodejs-npm-user-validate: improper input validation when validating user emails leads to ReDoS (CVE-2020-7754)</p>
<p>* nodejs-y18n: prototype pollution vulnerability (CVE-2020-7774)</p>
<p>* nodejs-ini: prototype pollution via malicious INI file (CVE-2020-7788)</p>
<p>* nodejs-dot-prop: prototype pollution (CVE-2020-8116)</p>
<p>* nodejs: use-after-free in the TLS implementation (CVE-2020-8265)</p>
<p>* npm: sensitive information exposure through logs (CVE-2020-15095)</p>
<p>* nodejs-ajv: prototype pollution via crafted JSON schema in ajv.validate function (CVE-2020-15366)</p>
<p>* nodejs-yargs-parser: prototype pollution vulnerability (CVE-2020-7608)</p>
<p>* nodejs: HTTP request smuggling via two copies of a header field in an http request (CVE-2020-8287)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2021:0548"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-01510</id>
    <title>bdu:2024-01510</title>
    <updated>2026-10-02T20:14:33.068924+00:00</updated>
    <content>bdu:2024-01510</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-01510"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0575</id>
    <title>certfr-2024-avi-0575 — De multiples vulnérabilités ont été découvertes dans les produits Juniper Networks. Certaines d'entre elles permettent…</title>
    <updated>2026-10-02T20:14:33.068941+00:00</updated>
    <content>certfr-2024-avi-0575</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0575"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-185774</id>
    <title>EUVD-2026-185774</title>
    <updated>2026-10-02T20:14:33.068958+00:00</updated>
    <content>EUVD-2026-185774</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-185774"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-7754</id>
    <title>fkie_cve-2020-7754</title>
    <updated>2026-10-02T20:14:33.068969+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>This affects the package npm-user-validate before 1.0.1. The regex that validates user emails took exponentially longer to process long input strings beginning with @ characters.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-7754"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-pw54-mh39-w3hc</id>
    <title>GHSA-pw54-mh39-w3hc — Regular expression denial of service in npm-user-validate</title>
    <updated>2026-10-02T20:14:33.068989+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: npm-user-validate</p>
<p>This affects the package npm-user-validate before 1.0.1. The regex that validates user emails took exponentially longer to process long input strings beginning with @ characters.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-pw54-mh39-w3hc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-7754</id>
    <title>gsd-2020-7754</title>
    <updated>2026-10-02T20:14:33.069009+00:00</updated>
    <content>gsd-2020-7754</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-7754"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1769</id>
    <title>OESA-2022-1769 — nodejs security update</title>
    <updated>2026-10-02T20:14:33.069020+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: nodejs, openEuler:20.03-LTS-SP3: nodejs</p>
<p>Node.js is a platform built on Chrome&amp;apos;s JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices.

Security Fix(es):

Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like &amp;quot;&amp;lt;protocol&amp;gt;://[&amp;lt;user&amp;gt;[:&amp;lt;password&amp;gt;]@]&amp;lt;hostname&amp;gt;[:&amp;lt;port&amp;gt;][:][/]&amp;lt;path&amp;gt;&amp;quot;. The password value is not redacted and is printed to stdout and also to any generated log files.(CVE-2020-15095)</p>
<p>This affects the package y18n before 3.2.2, 4.0.1 and 5.0.5. PoC by po6ix: const y18n = require( y18n )(); y18n.setLocale( proto ); y18n.updateLocale({polluted: true}); console.log(polluted); // true(CVE-2020-7774)</p>
<p>This affects the package npm-user-validate before 1.0.1. The regex that validates user emails took exponentially longer to process long input strings beginning with @ characters.(CVE-2020-7754)</p>
<p>This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context.(CVE-2020-7788)</p>
<p>json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ( Prototype Pollution )(CVE-2021-39…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1769"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:0421</id>
    <title>RHSA-2021:0421 — Red Hat Security Advisory: rh-nodejs14-nodejs security update</title>
    <updated>2026-10-02T20:14:33.069058+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>nodejs-npm-user-validate: improper input validation when validating user emails leads to ReDoS nodejs-y18n: prototype pollution vulnerability nodejs-ini: Prototype pollution via malicious INI file nodejs: use-after-free in the TLS implementation c-ares: ares_parse_{a,aaaa}_reply() insufficient naddrttls validation DoS nodejs: HTTP request smuggling via two copies of a header field in an http request nodejs-ajv: prototype pollution via crafted JSON schema in ajv.validate function</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:0421"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:0548</id>
    <title>RHSA-2021:0548 — Red Hat Security Advisory: nodejs:10 security update</title>
    <updated>2026-10-02T20:14:33.069087+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>nodejs-yargs-parser: prototype pollution vulnerability nodejs-npm-user-validate: improper input validation when validating user emails leads to ReDoS nodejs-y18n: prototype pollution vulnerability nodejs-ini: Prototype pollution via malicious INI file nodejs-dot-prop: prototype pollution libuv: buffer overflow in realpath nodejs: use-after-free in the TLS implementation nodejs: HTTP request smuggling via two copies of a header field in an http request npm: sensitive information exposure through logs nodejs-ajv: prototype pollution via crafted JSON schema in ajv.validate function</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:0548"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1591</id>
    <title>WID-SEC-W-2024-1591 — Juniper JUNOS: Mehrere Schwachstellen</title>
    <updated>2026-10-02T20:14:33.069113+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Juniper JUNOS ausnutzen, um einen Denial of Service  zu verursachen, Informationen offenzulegen, Privilegien zu erweitern und Sicherheitsmechanismen inklusive zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1591"/>
  </entry>
</feed>
