<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T14:47:48.840340+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-09400</id>
    <title>bdu:2026-09400</title>
    <updated>2026-10-03T14:47:48.920626+00:00</updated>
    <content>bdu:2026-09400</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-09400"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0258</id>
    <title>certfr-2023-avi-0258 — De multiples vulnérabilités ont été découvertes dans les produits &lt;span
class="textit"&gt;IBM&lt;/span&gt;. Elles permettent à u…</title>
    <updated>2026-10-03T14:47:48.920665+00:00</updated>
    <content>certfr-2023-avi-0258</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0258"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-221818</id>
    <title>EUVD-2026-221818</title>
    <updated>2026-10-03T14:47:48.920686+00:00</updated>
    <content>EUVD-2026-221818</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-221818"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-2421</id>
    <title>fkie_cve-2022-2421</title>
    <updated>2026-10-03T14:47:48.920697+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Due to improper type validation in attachment parsing the Socket.io js library, it is possible to overwrite the _placeholder object which allows an attacker to place references to functions at arbitrary places in the resulting query object.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-2421"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qm95-pgcg-qqfq</id>
    <title>GHSA-qm95-pgcg-qqfq — Insufficient validation when decoding a Socket.IO packet</title>
    <updated>2026-10-03T14:47:48.920725+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: socket.io-parser</p>
<p>Due to improper type validation in the `socket.io-parser` library (which is used by the `socket.io` and `socket.io-client` packages to encode and decode Socket.IO packets), it is possible to overwrite the _placeholder object which allows an attacker to place references to functions at arbitrary places in the resulting query object.</p>
<p>Example:</p>
<p>```js
const decoder = new Decoder();</p>
<p>decoder.on("decoded", (packet) =&gt; {
 console.log(packet.data); // prints [ 'hello', [Function: splice] ]
})</p>
<p>decoder.add('51-["hello",{"_placeholder":true,"num":"splice"}]');
decoder.add(Buffer.from("world"));
```</p>
<p>This bubbles up in the `socket.io` package:</p>
<p>```js
io.on("connection", (socket) =&gt; {
 socket.on("hello", (val) =&gt; {
 // here, "val" could be a function instead of a buffer
 });
});
```</p>
<p>:warning: IMPORTANT NOTE :warning:</p>
<p>You need to make sure that the payload that you received from the client is actually a `Buffer` object:</p>
<p>```js
io.on("connection", (socket) =&gt; {
 socket.on("hello", (val) =&gt; {
 if (!Buffer.isBuffer(val)) {
 socket.disconnect();
 return;
 }
 // ...
 });
});
```</p>
<p>**If that's already the case, then you are not impacted by this issue, and there is no way an attacker could make your server crash (or escalate privileges, ...).**</p>
<p>Example of values that could be sent by a malicious user:</p>
<p>- a number that is out of bounds</p>
<p>Sample packet: `451-["hello",{"_placeholder":true,"num":10}]`</p>
<p>```js
io.on("connection", (socket) =&gt; {
 socket.on("hello", (val) =&gt; {
 // val is `undefined`…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qm95-pgcg-qqfq"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-2421</id>
    <title>gsd-2022-2421</title>
    <updated>2026-10-03T14:47:48.920792+00:00</updated>
    <content>gsd-2022-2421</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-2421"/>
  </entry>
</feed>
