<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T00:05:19.843371+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-232670</id>
    <title>EUVD-2026-232670</title>
    <updated>2026-10-04T00:05:19.981064+00:00</updated>
    <content>EUVD-2026-232670</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-232670"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-31150</id>
    <title>fkie_cve-2022-31150</title>
    <updated>2026-10-04T00:05:19.981105+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>undici is an HTTP/1.1 client, written from scratch for Node.js. It is possible to inject CRLF sequences into request headers in undici in versions less than 5.7.1. A fix was released in version 5.8.0. Sanitizing all HTTP headers from untrusted sources to eliminate `\r\n` is a workaround for this issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-31150"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3cvr-822r-rqcc</id>
    <title>GHSA-3cvr-822r-rqcc — undici before v5.8.0 vulnerable to CRLF injection in request headers</title>
    <updated>2026-10-04T00:05:19.981139+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: undici</p>
<p>### Impact</p>
<p>It is possible to inject CRLF sequences into request headers in Undici.</p>
<p>```js
const undici = require('undici')</p>
<p>const response = undici.request("http://127.0.0.1:1000", {
  headers: {'a': "\r\nb"}
})
```</p>
<p>The same applies to `path` and `method`</p>
<p>### Patches</p>
<p>Update to v5.8.0</p>
<p>### Workarounds</p>
<p>Sanitize all HTTP headers from untrusted sources to eliminate `\r\n`.</p>
<p>### References</p>
<p>https://hackerone.com/reports/409943
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12116</p>
<p>### For more information</p>
<p>If you have any questions or comments about this advisory:</p>
<p>* Open an issue in [undici repository](https://github.com/nodejs/undici/issues)
* To make a report, follow the [SECURITY](https://github.com/nodejs/node/blob/HEAD/SECURITY.md) document</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3cvr-822r-rqcc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-31150</id>
    <title>gsd-2022-31150</title>
    <updated>2026-10-04T00:05:19.981179+00:00</updated>
    <content>gsd-2022-31150</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-31150"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12285-1</id>
    <title>openSUSE-SU-2024:12285-1 — corepack16-16.17.0-2.1 on GA media</title>
    <updated>2026-10-04T00:05:19.981192+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>corepack16-16.17.0-2.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12285-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:6696</id>
    <title>RHSA-2022:6696 — Red Hat Security Advisory: Red Hat Advanced Cluster Management 2.4.6 security update and bug fixes</title>
    <updated>2026-10-04T00:05:19.981211+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang: crypto/tls: session tickets lack random ticket_age_add moment: inefficient parsing algorithm resulting in DoS nodejs16: CRLF injection in node-undici nodejs/undici: Cookie headers uncleared on cross-origin redirect vm2: Sandbox Escape in vm2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:6696"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:3196-1</id>
    <title>SUSE-SU-2022:3196-1 — Security update for nodejs16</title>
    <updated>2026-10-04T00:05:19.981234+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for nodejs16</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:3196-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-31150</id>
    <title>UBUNTU-CVE-2022-31150</title>
    <updated>2026-10-04T00:05:19.981250+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:24.04:LTS: node-undici, Ubuntu:25.10: node-undici, Ubuntu:26.04:LTS: node-undici</p>
<p>undici is an HTTP/1.1 client, written from scratch for Node.js. It is possible to inject CRLF sequences into request headers in undici in versions less than 5.7.1. A fix was released in version 5.8.0. Sanitizing all HTTP headers from untrusted sources to eliminate `\r\n` is a workaround for this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-31150"/>
  </entry>
</feed>
