<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:56:51.369412+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-232654</id>
    <title>EUVD-2026-232654</title>
    <updated>2026-10-02T14:56:51.476266+00:00</updated>
    <content>EUVD-2026-232654</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-232654"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-35949</id>
    <title>fkie_cve-2022-35949</title>
    <updated>2026-10-02T14:56:51.476320+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>undici is an HTTP/1.1 client, written from scratch for Node.js.`undici` is vulnerable to SSRF (Server-side Request Forgery) when an application takes in **user input** into the `path/pathname` option of `undici.request`. If a user specifies a URL such as `http://127.0.0.1` or `//127.0.0.1` ```js const undici = require("undici") undici.request({origin: "http://example.com", pathname: "//127.0.0.1"}) ``` Instead of processing the request as `http://example.org//127.0.0.1` (or `http://example.org/http://127.0.0.1` when `http://127.0.0.1 is used`), it actually processes the request as `http://127.0.0.1/` and sends it to `http://127.0.0.1`. If a developer passes in user input into `path` parameter of `undici.request`, it can result in an _SSRF_ as they will assume that the hostname cannot change, when in actual fact it can change because the specified path parameter is combined with the base URL. This issue was fixed in `undici@5.8.1`. The best workaround is to validate user input before passing it to the `undici.request` call.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-35949"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8qr4-xgw6-wmr3</id>
    <title>GHSA-8qr4-xgw6-wmr3 — `undici.request` vulnerable to SSRF using absolute URL on `pathname`</title>
    <updated>2026-10-02T14:56:51.476379+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: undici</p>
<p>### Impact</p>
<p>`undici` is vulnerable to SSRF (Server-side Request Forgery) when an application takes in **user input** into the `path/pathname` option of `undici.request`.</p>
<p>If a user specifies a URL such as `http://127.0.0.1` or `//127.0.0.1`</p>
<p>```js
const undici = require("undici")
undici.request({origin: "http://example.com", pathname: "//127.0.0.1"})
```</p>
<p>Instead of processing the request as `http://example.org//127.0.0.1` (or `http://example.org/http://127.0.0.1` when `http://127.0.0.1 is used`), it actually processes the request as `http://127.0.0.1/` and sends it to `http://127.0.0.1`.</p>
<p>If a developer passes in user input into `path` parameter of `undici.request`, it can result in an _SSRF_ as they will assume that the hostname cannot change, when in actual fact it can change because the specified path parameter is combined with the base URL.</p>
<p>### Patches</p>
<p>This issue was fixed in `undici@5.8.1`.</p>
<p>### Workarounds</p>
<p>The best workaround is to validate user input before passing it to the `undici.request` call.</p>
<p>## For more information
If you have any questions or comments about this advisory:</p>
<p>- Open an issue in [undici repository](https://github.com/nodejs/undici/issues)
- To make a report, follow the [SECURITY](https://github.com/nodejs/node/blob/HEAD/SECURITY.md) document</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8qr4-xgw6-wmr3"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-35949</id>
    <title>gsd-2022-35949</title>
    <updated>2026-10-02T14:56:51.476455+00:00</updated>
    <content>gsd-2022-35949</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-35949"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12285-1</id>
    <title>openSUSE-SU-2024:12285-1 — corepack16-16.17.0-2.1 on GA media</title>
    <updated>2026-10-02T14:56:51.476477+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>corepack16-16.17.0-2.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12285-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:7276</id>
    <title>RHSA-2022:7276 — Red Hat Security Advisory: Red Hat Advanced Cluster Management 2.4.8 security fixes and container updates</title>
    <updated>2026-10-02T14:56:51.476512+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>search-api: SQL injection leads to remote denial of service terser: insecure use of regular expressions leads to ReDoS moment: inefficient parsing algorithm resulting in DoS nodejs: undici vulnerable to CRLF via content headers nodejs: undici.request vulnerable to SSRF</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:7276"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:3196-1</id>
    <title>SUSE-SU-2022:3196-1 — Security update for nodejs16</title>
    <updated>2026-10-02T14:56:51.476553+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for nodejs16</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:3196-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1933</id>
    <title>WID-SEC-W-2022-1933 — Red Hat Satellite und Red Hat Enterprise Linux: Mehrere Schwachstellen</title>
    <updated>2026-10-02T14:56:51.476582+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Satellite und Red Hat Enterprise Linux ausnutzen, um einen Denial of Service oder nicht spezifizierten Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1933"/>
  </entry>
</feed>
