<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T06:17:08.547412+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-233367</id>
    <title>EUVD-2026-233367</title>
    <updated>2026-10-03T06:17:08.615279+00:00</updated>
    <content>EUVD-2026-233367</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-233367"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-46164</id>
    <title>fkie_cve-2022-46164</title>
    <updated>2026-10-03T06:17:08.615317+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>NodeBB is an open source Node.js based forum software. Due to a plain object with a prototype being used in socket.io message handling a specially crafted payload can be used to impersonate other users and takeover accounts. This vulnerability has been patched in version 2.6.1. Users are advised to upgrade. Users unable to upgrade may cherry-pick commit `48d143921753914da45926cca6370a92ed0c46b8` into their codebase to patch the exploit.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-46164"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rf3g-v8p5-p675</id>
    <title>GHSA-rf3g-v8p5-p675 — NodeBB vulnerable to account takeover via prototype vulnerability</title>
    <updated>2026-10-03T06:17:08.615350+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: nodebb</p>
<p>### Impact
Due to a plain object with a prototype being used in socket.io message handling a specially crafted payload can be used to impersonate other users and takeover accounts.</p>
<p>### Patches
Patched in 2.6.1</p>
<p>### Workarounds
Site maintainers can cherry-pick https://github.com/NodeBB/NodeBB/commit/48d143921753914da45926cca6370a92ed0c46b8 into their codebase to patch the exploit.</p>
<p>### For more information
If you have any questions or comments about this advisory:</p>
<p>Discuss it on [our community forum](https://github.com/NodeBB/NodeBB/security/advisories/community.nodebb.org/)
Email us at [support@nodebb.org](mailto:support@nodebb.org)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rf3g-v8p5-p675"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-46164</id>
    <title>gsd-2022-46164</title>
    <updated>2026-10-03T06:17:08.615381+00:00</updated>
    <content>gsd-2022-46164</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-46164"/>
  </entry>
</feed>
