<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T16:04:00.213574+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2022:9073</id>
    <title>ALSA-2022:9073 — Moderate: nodejs:16 security, bug fix, and enhancement update</title>
    <updated>2026-10-03T16:04:00.925129+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: nodejs, AlmaLinux:8: nodejs-devel, AlmaLinux:8: nodejs-docs, AlmaLinux:8: nodejs-full-i18n, AlmaLinux:8: nodejs-nodemon, AlmaLinux:8: nodejs-packaging, AlmaLinux:8: npm</p>
<p>Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.</p>
<p>The following packages were updated to later upstream versions: nodejs (16.18.1), nodejs-nodemon (2.0.20).</p>
<p>Security Fix(es):</p>
<p>* nodejs: Improper handling of URI Subject Alternative Names (CVE-2021-44531)
* nodejs: Certificate Verification Bypass via String Injection (CVE-2021-44532)
* nodejs: Incorrect handling of certificate subject and issuer fields (CVE-2021-44533)
* minimist: prototype pollution (CVE-2021-44906)
* nodejs-minimatch: ReDoS via the braceExpand function (CVE-2022-3517)
* nodejs: DNS rebinding in inspect via invalid octal IP address (CVE-2022-43548)
* nodejs: Prototype pollution via console.table properties (CVE-2022-21824)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Bug Fix(es):</p>
<p>* nodejs:16/nodejs: Packaged version of undici does not fit with declared version. [almalinux-8] (BZ#2151625)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2022:9073"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-01534</id>
    <title>bdu:2024-01534</title>
    <updated>2026-10-03T16:04:00.925253+00:00</updated>
    <content>bdu:2024-01534</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-01534"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-767</id>
    <title>certfr-2022-avi-767 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T16:04:00.925273+00:00</updated>
    <content>certfr-2022-avi-767</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-767"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2022-25210</id>
    <title>cnvd-2022-25210</title>
    <updated>2026-10-03T16:04:00.925290+00:00</updated>
    <content>cnvd-2022-25210</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2022-25210"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-33159</id>
    <title>EUVD-2026-33159</title>
    <updated>2026-10-03T16:04:00.925302+00:00</updated>
    <content>EUVD-2026-33159</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-33159"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-44906</id>
    <title>fkie_cve-2021-44906</title>
    <updated>2026-10-03T16:04:00.925312+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Minimist &lt;=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-44906"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xvch-5gv4-984h</id>
    <title>GHSA-xvch-5gv4-984h — Prototype Pollution in minimist</title>
    <updated>2026-10-03T16:04:00.925334+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: minimist</p>
<p>Minimist prior to 1.2.6 and 0.2.4 is vulnerable to Prototype Pollution via file `index.js`, function `setKey()` (lines 69-95).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xvch-5gv4-984h"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-44906</id>
    <title>gsd-2021-44906</title>
    <updated>2026-10-03T16:04:00.925355+00:00</updated>
    <content>gsd-2021-44906</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-44906"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0325</id>
    <title>NCSC-2026-0325 — Kwetsbaarheden verholpen in Atlassian producten</title>
    <updated>2026-10-03T16:04:00.925366+00:00</updated>
    <content>NCSC-2026-0325</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0325"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1665</id>
    <title>OESA-2022-1665 — nodejs-minimist security update</title>
    <updated>2026-10-03T16:04:00.925486+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: nodejs-minimist, openEuler:20.03-LTS-SP3: nodejs-minimist, openEuler:22.03-LTS: nodejs-minimist</p>
<p>This module is the guts of optimist's argument parser without all the fanciful decoration.</p>
<p>Security Fix(es):</p>
<p>Minimist &amp;lt;=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).(CVE-2021-44906)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1665"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:1739</id>
    <title>RHSA-2022:1739 — Red Hat Security Advisory: Red Hat OpenShift Service Mesh 2.1.2.1 containers security update</title>
    <updated>2026-10-03T16:04:00.925512+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>minimist: prototype pollution node-fetch: exposure of sensitive information to an unauthorized actor follow-redirects: Exposure of Sensitive Information via Authorization Header leak node-forge: Signature verification leniency in checking `digestAlgorithm` structure can lead to signature forgery node-forge: Signature verification failing to check tailing garbage bytes can lead to signature forgery node-forge: Signature verification leniency in checking `DigestInfo` structure</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:1739"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:9073</id>
    <title>RHSA-2022:9073 — Red Hat Security Advisory: nodejs:16 security, bug fix, and enhancement update</title>
    <updated>2026-10-03T16:04:00.925539+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>nodejs: Improper handling of URI Subject Alternative Names nodejs: Certificate Verification Bypass via String Injection nodejs: Incorrect handling of certificate subject and issuer fields minimist: prototype pollution nodejs-minimatch: ReDoS via the braceExpand function nodejs: Prototype pollution via console.table properties nodejs: DNS rebinding in inspect via invalid octal IP address</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:9073"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:1459-1</id>
    <title>SUSE-SU-2022:1459-1 — Security update for nodejs14</title>
    <updated>2026-10-03T16:04:00.925564+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for nodejs14</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:1459-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-44906</id>
    <title>UBUNTU-CVE-2021-44906</title>
    <updated>2026-10-03T16:04:00.925581+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: node-minimist, Ubuntu:18.04:LTS: node-minimist, Ubuntu:20.04:LTS: node-minimist, Ubuntu:22.04:LTS: node-minimist, Ubuntu:24.04:LTS: node-minimist, Ubuntu:25.10: node-minimist, Ubuntu:26.04:LTS: node-minimist</p>
<p>Minimist &lt;=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-44906"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0417</id>
    <title>WID-SEC-W-2022-0417 — Red Hat OpenShift Service Mesh: Mehrere Schwachstellen</title>
    <updated>2026-10-03T16:04:00.925609+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat OpenShift Service Mesh ausnutzen, um Dateien zu manipulieren, Informationen offenzulegen oder einen Denial of Service Zustand herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0417"/>
  </entry>
</feed>
