<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T17:18:52.966636+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-09399</id>
    <title>bdu:2026-09399</title>
    <updated>2026-10-02T17:18:53.075120+00:00</updated>
    <content>bdu:2026-09399</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-09399"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0015</id>
    <title>certfr-2024-avi-0015 — De multiples vulnérabilités ont été découvertes dans les produits
Splunk. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-02T17:18:53.075161+00:00</updated>
    <content>certfr-2024-avi-0015</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0015"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-210278</id>
    <title>EUVD-2026-210278</title>
    <updated>2026-10-02T17:18:53.075190+00:00</updated>
    <content>EUVD-2026-210278</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-210278"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-32695</id>
    <title>fkie_cve-2023-32695</title>
    <updated>2026-10-02T17:18:53.075211+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>socket.io parser is a socket.io encoder and decoder written in JavaScript complying with version 5 of socket.io-protocol. A specially crafted Socket.IO packet can trigger an uncaught exception on the Socket.IO server, thus killing the Node.js process. A patch has been released in version 4.2.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-32695"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-cqmj-92xf-r6r9</id>
    <title>GHSA-cqmj-92xf-r6r9 — Insufficient validation when decoding a Socket.IO packet</title>
    <updated>2026-10-02T17:18:53.075265+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: socket.io-parser</p>
<p>### Impact</p>
<p>A specially crafted Socket.IO packet can trigger an uncaught exception on the Socket.IO server, thus killing the Node.js process.</p>
<p>```
TypeError: Cannot convert object to primitive value
       at Socket.emit (node:events:507:25)
       at .../node_modules/socket.io/lib/socket.js:531:14
```</p>
<p>### Patches</p>
<p>A fix has been released today (2023/05/22):</p>
<p>- https://github.com/socketio/socket.io-parser/commit/3b78117bf6ba7e99d7a5cfc1ba54d0477554a7f3, included in `socket.io-parser@4.2.3`
- https://github.com/socketio/socket.io-parser/commit/2dc3c92622dad113b8676be06f23b1ed46b02ced, included in `socket.io-parser@3.4.3`</p>
<p>Another fix has been released for the `3.3.x` branch:</p>
<p>- https://github.com/socketio/socket.io-parser/commit/ee006607495eca4ec7262ad080dd3a91439a5ba4, included in `socket.io-parser@3.3.4</p>
<p>| `socket.io` version | `socket.io-parser` version                                                                              | Needs minor update?                  |
|---------------------|---------------------------------------------------------------------------------------------------------|--------------------------------------|
| `4.5.2...latest`    | `~4.2.0` ([ref](https://github.com/socketio/socket.io/commit/9890b036cf942f6b6ad2afeb6a8361c32cd5d528)) | `npm audit fix` should be sufficient |
| `4.1.3...4.5.1`     | `~4.1.1` ([ref](https://github.com/socketio/socket.io/commit/7c44893d7878cd5bba1eff43150c3e664f88fb57)) | Please upgrade to `socket.io@4.6.x`  |
| `3…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-cqmj-92xf-r6r9"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-32695</id>
    <title>gsd-2023-32695</title>
    <updated>2026-10-02T17:18:53.075315+00:00</updated>
    <content>gsd-2023-32695</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-32695"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-32695</id>
    <title>UBUNTU-CVE-2023-32695</title>
    <updated>2026-10-02T17:18:53.075328+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: node-socket.io-parser, Ubuntu:20.04:LTS: node-socket.io-parser, Ubuntu:22.04:LTS: node-socket.io-parser, Ubuntu:24.04:LTS: node-socket.io-parser</p>
<p>socket.io parser is a socket.io encoder and decoder written in JavaScript complying with version 5 of socket.io-protocol. A specially crafted Socket.IO packet can trigger an uncaught exception on the Socket.IO server, thus killing the Node.js process. A patch has been released in version 4.2.3.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-32695"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1800</id>
    <title>WID-SEC-W-2023-1800 — HCL BigFix: Mehrere Schwachstellen</title>
    <updated>2026-10-02T17:18:53.075353+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in HCL BigFix WebUI ausnutzen, um seine Privilegien zu erweitern, Dateien zu manipulieren, Informationen offenzulegen, Sicherheitsvorkehrungen zu umgehen oder einen Denial of Service Zustand herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1800"/>
  </entry>
</feed>
