<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T21:15:53.966678+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/9akk108470a8565</id>
    <title>9AKK108470A8565 — RMC-100 Vulnerability in the Web UI (REST Interface)</title>
    <updated>2026-10-04T21:15:54.372093+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An update is available that resolves a vulnerability in the product versions listed as affected in this advisory.
An attacker who successfully exploited this vulnerability could cause the web UI to stop.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/9akk108470a8565"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2023:0050</id>
    <title>ALSA-2023:0050 — Moderate: nodejs:14 security, bug fix, and enhancement update</title>
    <updated>2026-10-04T21:15:54.372149+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: nodejs, AlmaLinux:8: nodejs-devel, AlmaLinux:8: nodejs-docs, AlmaLinux:8: nodejs-full-i18n, AlmaLinux:8: nodejs-nodemon, AlmaLinux:8: nodejs-packaging, AlmaLinux:8: npm</p>
<p>Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.</p>
<p>The following packages have been upgraded to a later upstream version: nodejs (14.21.1), nodejs-nodemon (2.0.20).</p>
<p>Security Fix(es):</p>
<p>* minimist: prototype pollution (CVE-2021-44906)
* node-fetch: exposure of sensitive information to an unauthorized actor (CVE-2022-0235)
* nodejs-minimatch: ReDoS via the braceExpand function (CVE-2022-3517)
* express: "qs" prototype poisoning causes the hang of the node process (CVE-2022-24999)
* nodejs: DNS rebinding in inspect via invalid octal IP address (CVE-2022-43548)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2023:0050"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0276</id>
    <title>certfr-2023-avi-0276 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;IBM&lt;/span&gt;. Elles permettent à un attaquant d…</title>
    <updated>2026-10-04T21:15:54.372193+00:00</updated>
    <content>certfr-2023-avi-0276</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0276"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-235584</id>
    <title>EUVD-2026-235584</title>
    <updated>2026-10-04T21:15:54.372213+00:00</updated>
    <content>EUVD-2026-235584</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-235584"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-24999</id>
    <title>fkie_cve-2022-24999</title>
    <updated>2026-10-04T21:15:54.372226+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express application because an __ proto__ key can be used. In many typical Express use cases, an unauthenticated remote attacker can place the attack payload in the query string of the URL that is used to visit the application, such as a[__proto__]=b&amp;a[__proto__]&amp;a[length]=100000000. The fix was backported to qs 6.9.7, 6.8.3, 6.7.3, 6.6.1, 6.5.3, 6.4.1, 6.3.3, and 6.2.4 (and therefore Express 4.17.3, which has "deps: qs@6.9.7" in its release description, is not vulnerable).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-24999"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hrpp-h998-j3pp</id>
    <title>GHSA-hrpp-h998-j3pp — qs vulnerable to Prototype Pollution</title>
    <updated>2026-10-04T21:15:54.372251+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: qs</p>
<p>qs before 6.10.3 allows attackers to cause a Node process hang because an `__ proto__` key can be used. In many typical web framework use cases, an unauthenticated remote attacker can place the attack payload in the query string of the URL that is used to visit the application, such as `a[__proto__]=b&amp;a[__proto__]&amp;a[length]=100000000`. The fix was backported to qs 6.9.7, 6.8.3, 6.7.3, 6.6.1, 6.5.3, 6.4.1, 6.3.3, and 6.2.4.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hrpp-h998-j3pp"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-24999</id>
    <title>gsd-2022-24999</title>
    <updated>2026-10-04T21:15:54.372279+00:00</updated>
    <content>gsd-2022-24999</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-24999"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-25-084-01</id>
    <title>ICSA-25-084-01 — ABB RMC-100</title>
    <updated>2026-10-04T21:15:54.372291+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An update is available that resolves a vulnerability in the product versions listed as affected in this advisory.
An attacker who successfully exploited this vulnerability could cause the web UI to stop.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-25-084-01"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2022-24999</id>
    <title>msrc_CVE-2022-24999 — qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang fo…</title>
    <updated>2026-10-04T21:15:54.372308+00:00</updated>
    <content>msrc_CVE-2022-24999</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2022-24999"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-1338</id>
    <title>OESA-2024-1338 — nodejs-qs security update</title>
    <updated>2026-10-04T21:15:54.372326+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP3: nodejs-qs</p>
<p>This is a query string parser for node and the browser supporting nesting, as it was removed from 0.3.x, so this library provides the previous and commonly desired behavior (and twice as fast). Used by express, connect and others.

Security Fix(es):

qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express application because an __ proto__ key can be used. In many typical Express use cases, an unauthenticated remote attacker can place the attack payload in the query string of the URL that is used to visit the application, such as a[__proto__]=b&amp;amp;a[__proto__]&amp;amp;a[length]=100000000. The fix was backported to qs 6.9.7, 6.8.3, 6.7.3, 6.6.1, 6.5.3, 6.4.1, 6.3.3, and 6.2.4 (and therefore Express 4.17.3, which has &amp;quot;deps: qs@6.9.7&amp;quot; in its release description, is not vulnerable).(CVE-2022-24999)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-1338"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:0050</id>
    <title>RHSA-2023:0050 — Red Hat Security Advisory: nodejs:14 security, bug fix, and enhancement update</title>
    <updated>2026-10-04T21:15:54.372350+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>minimist: prototype pollution node-fetch: exposure of sensitive information to an unauthorized actor nodejs-minimatch: ReDoS via the braceExpand function express: "qs" prototype poisoning causes the hang of the node process nodejs: DNS rebinding in inspect via invalid octal IP address</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:0050"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:0612</id>
    <title>RHSA-2023:0612 — Red Hat Security Advisory: rh-nodejs14-nodejs and rh-nodejs14-nodejs-nodemon security update</title>
    <updated>2026-10-04T21:15:54.372376+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>glob-parent: Regular Expression Denial of Service minimist: prototype pollution node-fetch: exposure of sensitive information to an unauthorized actor nodejs-minimatch: ReDoS via the braceExpand function express: "qs" prototype poisoning causes the hang of the node process nodejs: DNS rebinding in inspect via invalid octal IP address</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:0612"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-24999</id>
    <title>UBUNTU-CVE-2022-24999</title>
    <updated>2026-10-04T21:15:54.372401+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:20.04:LTS: node-express, Ubuntu:Pro:20.04:LTS: node-qs</p>
<p>qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express application because an __ proto__ key can be used. In many typical Express use cases, an unauthenticated remote attacker can place the attack payload in the query string of the URL that is used to visit the application, such as a[__proto__]=b&amp;a[__proto__]&amp;a[length]=100000000. The fix was backported to qs 6.9.7, 6.8.3, 6.7.3, 6.6.1, 6.5.3, 6.4.1, 6.3.3, and 6.2.4 (and therefore Express 4.17.3, which has "deps: qs@6.9.7" in its release description, is not vulnerable).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-24999"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0398</id>
    <title>WID-SEC-W-2023-0398 — Red Hat Advanced Cluster Management for Kubernetes: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-04T21:15:54.372423+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle im Red Hat Advanced Cluster Management for Kubernetes ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0398"/>
  </entry>
</feed>
