<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T13:04:56.265760+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2022:4796</id>
    <title>ALSA-2022:4796 — Important: nodejs:16 security update</title>
    <updated>2026-10-02T13:04:56.416870+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: nodejs, AlmaLinux:8: nodejs-devel, AlmaLinux:8: nodejs-docs, AlmaLinux:8: nodejs-full-i18n, AlmaLinux:8: nodejs-nodemon, AlmaLinux:8: nodejs-packaging, AlmaLinux:8: npm</p>
<p>Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.</p>
<p>Security Fix(es):</p>
<p>* npm: npm ci succeeds when package-lock.json doesn't match package.json (CVE-2021-43616)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2022:4796"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2021-43616</id>
    <title>Withdrawn: BELL-CVE-2021-43616 — CVE-2021-43616 does not affect BellSoft software</title>
    <updated>2026-10-02T13:04:56.416937+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2021-43616"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-278</id>
    <title>certfr-2022-avi-278 — De multiples vulnérabilités ont été découvertes dans IBM Spectrum
discover. Certaines d'entre elles permettent à un att…</title>
    <updated>2026-10-02T13:04:56.416957+00:00</updated>
    <content>certfr-2022-avi-278</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-278"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ff52474</id>
    <title>CLEANSTART-2026-FF52474 — Security fix for CVE-2021-43616 applied in: npm 8.1.4-r0</title>
    <updated>2026-10-02T13:04:56.416973+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: npm</p>
<p>Security vulnerability affects the npm package. This issue is resolved in later releases. See references for vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ff52474"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-32647</id>
    <title>EUVD-2026-32647</title>
    <updated>2026-10-02T13:04:56.416993+00:00</updated>
    <content>EUVD-2026-32647</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-32647"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-43616</id>
    <title>fkie_cve-2021-43616</title>
    <updated>2026-10-02T13:04:56.417005+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json. This behavior is inconsistent with the documentation, and makes it easier for attackers to install malware that was supposed to have been blocked by an exact version match requirement in package-lock.json. NOTE: The npm team believes this is not a vulnerability. It would require someone to socially engineer package.json which has different dependencies than package-lock.json. That user would have to have file system or write access to change dependencies. The npm team states preventing malicious actors from socially engineering or gaining file system access is outside the scope of the npm CLI.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-43616"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-ppxp-px5q-gwqm</id>
    <title>GHSA-ppxp-px5q-gwqm</title>
    <updated>2026-10-02T13:04:56.417029+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json. This behavior is inconsistent with the documentation, and makes it easier for attackers to install malware that was supposed to have been blocked by an exact version match requirement in package-lock.json.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-ppxp-px5q-gwqm"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-43616</id>
    <title>gsd-2021-43616</title>
    <updated>2026-10-02T13:04:56.417043+00:00</updated>
    <content>gsd-2021-43616</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-43616"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:4796</id>
    <title>RHSA-2022:4796 — Red Hat Security Advisory: nodejs:16 security update</title>
    <updated>2026-10-02T13:04:56.417053+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>npm: npm ci succeeds when package-lock.json doesn't match package.json</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:4796"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-43616</id>
    <title>UBUNTU-CVE-2021-43616</title>
    <updated>2026-10-02T13:04:56.417070+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:22.04:LTS: npm, Ubuntu:24.04:LTS: npm, Ubuntu:25.10: npm, Ubuntu:26.04:LTS: npm</p>
<p>The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json. This behavior is inconsistent with the documentation, and makes it easier for attackers to install malware that was supposed to have been blocked by an exact version match requirement in package-lock.json. NOTE: The npm team believes this is not a vulnerability. It would require someone to socially engineer package.json which has different dependencies than package-lock.json. That user would have to have file system or write access to change dependencies. The npm team states preventing malicious actors from socially engineering or gaining file system access is outside the scope of the npm CLI.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-43616"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2278</id>
    <title>WID-SEC-W-2022-2278 — npm: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
    <updated>2026-10-02T13:04:56.417095+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in npm ausnutzen, um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2278"/>
  </entry>
</feed>
