<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:39:02.865349+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-05169</id>
    <title>bdu:2023-05169</title>
    <updated>2026-10-02T19:39:03.238769+00:00</updated>
    <content>bdu:2023-05169</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-05169"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0484</id>
    <title>certfr-2023-avi-0484 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
    <updated>2026-10-02T19:39:03.238814+00:00</updated>
    <content>certfr-2023-avi-0484</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0484"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-8348</id>
    <title>EUVD-2026-8348</title>
    <updated>2026-10-02T19:39:03.238834+00:00</updated>
    <content>EUVD-2026-8348</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-8348"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-28155</id>
    <title>fkie_cve-2023-28155</title>
    <updated>2026-10-02T19:39:03.238847+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-28155"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-p8p7-x288-28g6</id>
    <title>GHSA-p8p7-x288-28g6 — Server-Side Request Forgery in Request</title>
    <updated>2026-10-02T19:39:03.238877+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: request, npm: @cypress/request</p>
<p>The `request` package through 2.88.2 for Node.js and the `@cypress/request` package prior to 3.0.0 allow a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP).</p>
<p>NOTE: The `request` package is no longer supported by the maintainer.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-p8p7-x288-28g6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-28155</id>
    <title>gsd-2023-28155</title>
    <updated>2026-10-02T19:39:03.238906+00:00</updated>
    <content>gsd-2023-28155</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-28155"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2023-28155</id>
    <title>msrc_CVE-2023-28155 — The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server th…</title>
    <updated>2026-10-02T19:39:03.238918+00:00</updated>
    <content>msrc_CVE-2023-28155</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2023-28155"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:62115</id>
    <title>RHSA-2026:62115 — Red Hat Security Advisory: Red Hat Ceph Storage</title>
    <updated>2026-10-02T19:39:03.238936+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>taffy: taffydb: Internal Property Tampering containerd: OCI image importer memory exhaustion request: bypass of SSRF mitigations when following a cross-protocol redirect npm-serialize-javascript: Cross-site Scripting (XSS) in serialize-javascript urllib3: urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation urllib3: urllib3 does not control redirects in browsers and Node.js ip: Node ip SSRF urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:62115"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-28155</id>
    <title>UBUNTU-CVE-2023-28155</title>
    <updated>2026-10-02T19:39:03.238964+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: node-request, Ubuntu:16.04:LTS: node-request, Ubuntu:18.04:LTS: node-request, Ubuntu:20.04:LTS: node-request, Ubuntu:22.04:LTS: node-request, Ubuntu:24.04:LTS: node-request</p>
<p>The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-28155"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1800</id>
    <title>WID-SEC-W-2023-1800 — HCL BigFix: Mehrere Schwachstellen</title>
    <updated>2026-10-02T19:39:03.238993+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in HCL BigFix WebUI ausnutzen, um seine Privilegien zu erweitern, Dateien zu manipulieren, Informationen offenzulegen, Sicherheitsvorkehrungen zu umgehen oder einen Denial of Service Zustand herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1800"/>
  </entry>
</feed>
