<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T21:54:52.844378+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2021:3623</id>
    <title>ALSA-2021:3623 — Important: nodejs:12 security and bug fix update</title>
    <updated>2026-10-03T21:54:53.211006+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: nodejs, AlmaLinux:8: nodejs-devel, AlmaLinux:8: nodejs-docs, AlmaLinux:8: nodejs-full-i18n, AlmaLinux:8: nodejs-nodemon, AlmaLinux:8: nodejs-packaging, AlmaLinux:8: npm</p>
<p>Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.</p>
<p>Security Fix(es):</p>
<p>* nodejs: Use-after-free on close http2 on stream canceling (CVE-2021-22930)</p>
<p>* nodejs: Use-after-free on close http2 on stream canceling (CVE-2021-22940)</p>
<p>* c-ares: Missing input validation of host names may lead to domain hijacking (CVE-2021-3672)</p>
<p>* nodejs: Improper handling of untypical characters in domain names (CVE-2021-22931)</p>
<p>* nodejs-tar: Insufficient symlink protection allowing arbitrary file creation and overwrite (CVE-2021-32803)</p>
<p>* nodejs-tar: Insufficient absolute path sanitization allowing arbitrary file creation and overwrite (CVE-2021-32804)</p>
<p>* nodejs: Incomplete validation of tls rejectUnauthorized parameter (CVE-2021-22939)</p>
<p>* nodejs-path-parse: ReDoS via splitDeviceRe, splitTailRe and splitPathRe (CVE-2021-23343)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Bug Fix(es):</p>
<p>* nodejs:12/nodejs: Make FIPS options always available (BZ#1993927)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2021:3623"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-510</id>
    <title>certfr-2022-avi-510 — De multiples vulnérabilités ont été découvertes dans IBM QRadar.
Certaines d'entre elles permettent à un attaquant de p…</title>
    <updated>2026-10-03T21:54:53.211104+00:00</updated>
    <content>certfr-2022-avi-510</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-510"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-173755</id>
    <title>EUVD-2026-173755</title>
    <updated>2026-10-03T21:54:53.211127+00:00</updated>
    <content>EUVD-2026-173755</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-173755"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-23343</id>
    <title>fkie_cve-2021-23343</title>
    <updated>2026-10-03T21:54:53.211140+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>All versions of package path-parse are vulnerable to Regular Expression Denial of Service (ReDoS) via splitDeviceRe, splitTailRe, and splitPathRe regular expressions. ReDoS exhibits polynomial worst-case time complexity.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-23343"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hj48-42vr-x3v9</id>
    <title>GHSA-hj48-42vr-x3v9 — Regular Expression Denial of Service in path-parse</title>
    <updated>2026-10-03T21:54:53.211162+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: path-parse</p>
<p>Affected versions of npm package `path-parse` are vulnerable to Regular Expression Denial of Service (ReDoS) via splitDeviceRe, splitTailRe, and splitPathRe regular expressions. ReDoS exhibits polynomial worst-case time complexity.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hj48-42vr-x3v9"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-23343</id>
    <title>gsd-2021-23343</title>
    <updated>2026-10-03T21:54:53.211183+00:00</updated>
    <content>gsd-2021-23343</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-23343"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1262</id>
    <title>OESA-2021-1262 — nodejs-path-parse security update</title>
    <updated>2026-10-03T21:54:53.211194+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: nodejs-path-parse</p>
<p>Node.js path.parse() ponyfill

Security Fix(es):

All versions of package path-parse are vulnerable to Regular Expression Denial of Service (ReDoS) via splitDeviceRe, splitTailRe, and splitPathRe regular expressions. ReDoS exhibits polynomial worst-case time complexity.(CVE-2021-23343)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1262"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2022:0657-1</id>
    <title>openSUSE-SU-2022:0657-1 — Security update for nodejs12</title>
    <updated>2026-10-03T21:54:53.211216+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for nodejs12</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2022:0657-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:2865</id>
    <title>RHSA-2021:2865 — Red Hat Security Advisory: RHV Manager (ovirt-engine) security update [ovirt-4.4.7]</title>
    <updated>2026-10-03T21:54:53.211286+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>nodejs-ua-parser-js: Regular expression denial of service via the regex nodejs-glob-parent: Regular expression denial of service nodejs-path-parse: ReDoS via splitDeviceRe, splitTailRe and splitPathRe nodejs-underscore: Arbitrary code execution via the template function</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:2865"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:0531-1</id>
    <title>SUSE-SU-2022:0531-1 — Security update for nodejs12</title>
    <updated>2026-10-03T21:54:53.211312+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for nodejs12</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:0531-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0809</id>
    <title>WID-SEC-W-2023-0809 — IBM QRadar SIEM: Mehrere Schwachstellen</title>
    <updated>2026-10-03T21:54:53.211329+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um beliebigen Programmcode auszuführen, Informationen offenzulegen, Informationen falsch darzustellen, einen Denial of Service Zustand herbeizuführen, Sicherheitsvorkehrungen zu umgehen, einen Cross-Site-Scripting-Angriff durchzuführen oder unbekannte Auswirkungen zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0809"/>
  </entry>
</feed>
