<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T14:27:44.263724+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-216443</id>
    <title>EUVD-2026-216443</title>
    <updated>2026-10-04T14:27:44.335706+00:00</updated>
    <content>EUVD-2026-216443</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-216443"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-31125</id>
    <title>fkie_cve-2023-31125</title>
    <updated>2026-10-04T14:27:44.335745+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Socket.IO. An uncaught exception vulnerability was introduced in version 5.1.0 and included in version 4.1.0 of the `socket.io` parent package. Older versions are not impacted. A specially crafted HTTP request can trigger an uncaught exception on the Engine.IO server, thus killing the Node.js process. This impacts all the users of the `engine.io` package, including those who use depending packages like `socket.io`. This issue was fixed in version 6.4.2 of Engine.IO. There is no known workaround except upgrading to a safe version.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-31125"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-q9mw-68c2-j6m5</id>
    <title>GHSA-q9mw-68c2-j6m5 — engine.io Uncaught Exception vulnerability</title>
    <updated>2026-10-04T14:27:44.335781+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: engine.io</p>
<p>### Impact</p>
<p>A specially crafted HTTP request can trigger an uncaught exception on the Engine.IO server, thus killing the Node.js process.</p>
<p>```
TypeError: Cannot read properties of undefined (reading 'handlesUpgrades')
    at Server.onWebSocket (build/server.js:515:67)
```</p>
<p>This impacts all the users of the [`engine.io`](https://www.npmjs.com/package/engine.io) package, including those who uses depending packages like [`socket.io`](https://www.npmjs.com/package/socket.io).</p>
<p>### Patches</p>
<p>A fix has been released today (2023/05/02): [6.4.2](https://github.com/socketio/engine.io/releases/tag/6.4.2)</p>
<p>This bug was introduced in version 5.1.0 and included in version 4.1.0 of the `socket.io` parent package. Older versions are not impacted.</p>
<p>For `socket.io` users:</p>
<p>| Version range               | `engine.io` version | Needs minor update?                                                                                    |
|-----------------------------|---------------------|--------------------------------------------------------------------------------------------------------|
| `socket.io@4.6.x`           | `~6.4.0`            | `npm audit fix` should be sufficient                                                                   |
| `socket.io@4.5.x`           | `~6.2.0`            | Please upgrade to `socket.io@4.6.x`                                                                    |
| `socket.io@4.4.x`           | `~6.1.0`            | Please upgrade to `socket.io@4.6.x`…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-q9mw-68c2-j6m5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-31125</id>
    <title>gsd-2023-31125</title>
    <updated>2026-10-04T14:27:44.335831+00:00</updated>
    <content>gsd-2023-31125</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-31125"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1800</id>
    <title>WID-SEC-W-2023-1800 — HCL BigFix: Mehrere Schwachstellen</title>
    <updated>2026-10-04T14:27:44.335845+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in HCL BigFix WebUI ausnutzen, um seine Privilegien zu erweitern, Dateien zu manipulieren, Informationen offenzulegen, Sicherheitsvorkehrungen zu umgehen oder einen Denial of Service Zustand herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1800"/>
  </entry>
</feed>
