<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T12:12:05.188888+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2021:0548</id>
    <title>ALSA-2021:0548 — Moderate: nodejs:10 security update</title>
    <updated>2026-10-03T12:12:05.409797+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: nodejs-nodemon, AlmaLinux:8: nodejs-packaging</p>
<p>Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.</p>
<p>The following packages have been upgraded to a later upstream version: nodejs (10.23.1).</p>
<p>Security Fix(es):</p>
<p>* libuv: buffer overflow in realpath (CVE-2020-8252)</p>
<p>* nodejs-npm-user-validate: improper input validation when validating user emails leads to ReDoS (CVE-2020-7754)</p>
<p>* nodejs-y18n: prototype pollution vulnerability (CVE-2020-7774)</p>
<p>* nodejs-ini: prototype pollution via malicious INI file (CVE-2020-7788)</p>
<p>* nodejs-dot-prop: prototype pollution (CVE-2020-8116)</p>
<p>* nodejs: use-after-free in the TLS implementation (CVE-2020-8265)</p>
<p>* npm: sensitive information exposure through logs (CVE-2020-15095)</p>
<p>* nodejs-ajv: prototype pollution via crafted JSON schema in ajv.validate function (CVE-2020-15366)</p>
<p>* nodejs-yargs-parser: prototype pollution vulnerability (CVE-2020-7608)</p>
<p>* nodejs: HTTP request smuggling via two copies of a header field in an http request (CVE-2020-8287)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2021:0548"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-02874</id>
    <title>bdu:2021-02874</title>
    <updated>2026-10-03T12:12:05.409881+00:00</updated>
    <content>bdu:2021-02874</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-02874"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-510</id>
    <title>certfr-2022-avi-510 — De multiples vulnérabilités ont été découvertes dans IBM QRadar.
Certaines d'entre elles permettent à un attaquant de p…</title>
    <updated>2026-10-03T12:12:05.409899+00:00</updated>
    <content>certfr-2022-avi-510</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-510"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-176554</id>
    <title>EUVD-2026-176554</title>
    <updated>2026-10-03T12:12:05.409916+00:00</updated>
    <content>EUVD-2026-176554</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-176554"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-7788</id>
    <title>fkie_cve-2020-7788</title>
    <updated>2026-10-03T12:12:05.409927+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-7788"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qqgx-2p2h-9c37</id>
    <title>GHSA-qqgx-2p2h-9c37 — ini before 1.3.6 vulnerable to Prototype Pollution via ini.parse</title>
    <updated>2026-10-03T12:12:05.409950+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: ini</p>
<p>### Overview
The `ini` npm package before version 1.3.6 has a Prototype Pollution vulnerability.</p>
<p>If an attacker submits a malicious INI file to an application that parses it with `ini.parse`, they will pollute the prototype on the application. This can be exploited further depending on the context.</p>
<p>### Patches</p>
<p>This has been patched in 1.3.6.</p>
<p>### Steps to reproduce</p>
<p>payload.ini
```
[__proto__]
polluted = "polluted"
```</p>
<p>poc.js:
```
var fs = require('fs')
var ini = require('ini')</p>
<p>var parsed = ini.parse(fs.readFileSync('./payload.ini', 'utf-8'))
console.log(parsed)
console.log(parsed.__proto__)
console.log(polluted)
```</p>
<p>```
&gt; node poc.js
{}
{ polluted: 'polluted' }
{ polluted: 'polluted' }
polluted
```</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qqgx-2p2h-9c37"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-7788</id>
    <title>gsd-2020-7788</title>
    <updated>2026-10-03T12:12:05.409981+00:00</updated>
    <content>gsd-2020-7788</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-7788"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1769</id>
    <title>OESA-2022-1769 — nodejs security update</title>
    <updated>2026-10-03T12:12:05.409992+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: nodejs, openEuler:20.03-LTS-SP3: nodejs</p>
<p>Node.js is a platform built on Chrome&amp;apos;s JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices.

Security Fix(es):

Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like &amp;quot;&amp;lt;protocol&amp;gt;://[&amp;lt;user&amp;gt;[:&amp;lt;password&amp;gt;]@]&amp;lt;hostname&amp;gt;[:&amp;lt;port&amp;gt;][:][/]&amp;lt;path&amp;gt;&amp;quot;. The password value is not redacted and is printed to stdout and also to any generated log files.(CVE-2020-15095)</p>
<p>This affects the package y18n before 3.2.2, 4.0.1 and 5.0.5. PoC by po6ix: const y18n = require( y18n )(); y18n.setLocale( proto ); y18n.updateLocale({polluted: true}); console.log(polluted); // true(CVE-2020-7774)</p>
<p>This affects the package npm-user-validate before 1.0.1. The regex that validates user emails took exponentially longer to process long input strings beginning with @ characters.(CVE-2020-7754)</p>
<p>This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context.(CVE-2020-7788)</p>
<p>json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ( Prototype Pollution )(CVE-2021-39…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1769"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:0421</id>
    <title>RHSA-2021:0421 — Red Hat Security Advisory: rh-nodejs14-nodejs security update</title>
    <updated>2026-10-03T12:12:05.410031+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>nodejs-npm-user-validate: improper input validation when validating user emails leads to ReDoS nodejs-y18n: prototype pollution vulnerability nodejs-ini: Prototype pollution via malicious INI file nodejs: use-after-free in the TLS implementation c-ares: ares_parse_{a,aaaa}_reply() insufficient naddrttls validation DoS nodejs: HTTP request smuggling via two copies of a header field in an http request nodejs-ajv: prototype pollution via crafted JSON schema in ajv.validate function</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:0421"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:0548</id>
    <title>RHSA-2021:0548 — Red Hat Security Advisory: nodejs:10 security update</title>
    <updated>2026-10-03T12:12:05.410060+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>nodejs-yargs-parser: prototype pollution vulnerability nodejs-npm-user-validate: improper input validation when validating user emails leads to ReDoS nodejs-y18n: prototype pollution vulnerability nodejs-ini: Prototype pollution via malicious INI file nodejs-dot-prop: prototype pollution libuv: buffer overflow in realpath nodejs: use-after-free in the TLS implementation nodejs: HTTP request smuggling via two copies of a header field in an http request npm: sensitive information exposure through logs nodejs-ajv: prototype pollution via crafted JSON schema in ajv.validate function</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:0548"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-7788</id>
    <title>UBUNTU-CVE-2020-7788</title>
    <updated>2026-10-03T12:12:05.410091+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: node-ini, Ubuntu:16.04:LTS: node-ini, Ubuntu:18.04:LTS: node-ini, Ubuntu:20.04:LTS: node-ini, Ubuntu:22.04:LTS: node-ini, Ubuntu:24.04:LTS: node-ini, Ubuntu:25.10: node-ini, Ubuntu:26.04:LTS: node-ini</p>
<p>This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-7788"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1603</id>
    <title>WID-SEC-W-2022-1603 — IBM Tivoli Netcool/OMNIbus: Mehrere Schwachstellen</title>
    <updated>2026-10-03T12:12:05.410120+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM Tivoli Netcool/OMNIbus ausnutzen, um beliebigen Programmcode auszuführen, Informationen offenzulegen, Dateien zu manipulieren oder einen Denial of Service Zustand herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1603"/>
  </entry>
</feed>
