<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T11:24:00.187421+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0010</id>
    <title>certfr-2024-avi-0010 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
    <updated>2026-10-04T11:24:00.342631+00:00</updated>
    <content>certfr-2024-avi-0010</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0010"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-187570</id>
    <title>EUVD-2026-187570</title>
    <updated>2026-10-04T11:24:00.342698+00:00</updated>
    <content>EUVD-2026-187570</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-187570"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-43646</id>
    <title>fkie_cve-2023-43646</title>
    <updated>2026-10-04T11:24:00.342716+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>get-func-name is a module to retrieve a function's name securely and consistently both in NodeJS and the browser. Versions prior to 2.0.1 are subject to a regular expression denial of service (redos) vulnerability which may lead to a denial of service when parsing malicious input. This vulnerability can be exploited when there is an imbalance in parentheses, which results in excessive backtracking and subsequently increases the CPU load and processing time significantly. This vulnerability can be triggered using the following input: '\t'.repeat(54773) + '\t/function/i'. This issue has been addressed in commit `f934b228b` which has been included in releases from 2.0.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-43646"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4q6p-r6v2-jvc5</id>
    <title>GHSA-4q6p-r6v2-jvc5 — Chaijs/get-func-name vulnerable to ReDoS</title>
    <updated>2026-10-04T11:24:00.342754+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: get-func-name</p>
<p>The current regex implementation for parsing values in the module is susceptible to excessive backtracking, leading to potential DoS attacks. The regex implementation in question is as follows:</p>
<p>```js
const functionNameMatch = /\s*function(?:\s|\s*\/\*[^(?:*/)]+\*\/\s*)*([^\s(/]+)/;
```</p>
<p>This vulnerability can be exploited when there is an imbalance in parentheses, which results in excessive backtracking and subsequently increases the CPU load and processing time significantly. This vulnerability can be triggered using the following input:</p>
<p>```js
'\t'.repeat(54773) + '\t/function/i'
```</p>
<p>Here is a simple PoC code to demonstrate the issue:</p>
<p>```js
const protocolre = /\sfunction(?:\s|\s/*[^(?:*\/)]+*/\s*)*([^\(\/]+)/;</p>
<p>const startTime = Date.now();
const maliciousInput = '\t'.repeat(54773) + '\t/function/i'</p>
<p>protocolre.test(maliciousInput);</p>
<p>const endTime = Date.now();</p>
<p>console.log("process time: ", endTime - startTime, "ms");
```</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4q6p-r6v2-jvc5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-43646</id>
    <title>gsd-2023-43646</title>
    <updated>2026-10-04T11:24:00.342792+00:00</updated>
    <content>gsd-2023-43646</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-43646"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:1383</id>
    <title>RHSA-2024:1383 — Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.15.0 security, enhancement, &amp; bug fix update</title>
    <updated>2026-10-04T11:24:00.342805+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>rpm: TOCTOU race in checks for unsafe symlinks rpm: races with chown/chmod/capabilities calls during installation rpm: checks for unsafe symlinks are not performed for intermediary directories Hashicorp/vault: Vault’s LDAP Auth Method Allows for User Enumeration openssl: Incorrect cipher key and IV length processing vault: inbound client requests can trigger a denial of service gnutls: timing side-channel in the RSA-PSK authentication sqlite: heap-buffer-overflow at sessionfuzz golang: crypto/internal/nistec: specific unreduced P-256 scalars produce incorrect results follow-redirects: Improper Input Validation due to the improper handling of URLs by the url.parse() python: Parsing errors in email/_parseaddr.py lead to incorrect value in email address part of tuple sudo: Sudo does not escape control characters in log messages sudo: Sudo does not escape control characters in sudoreplay output golang: net/http: insufficient sanitization of Host header golang: crypto/tls: slow verification of certificate chains containing large RSA keys golang: html/template: improper handling of HTML-like comments within script contexts golang: html/template: improper handling of special tags within script contexts golang: crypto/tls: panic when processing post-handshake message on QUIC connections golang: crypto/tls: lack of a limit on buffered post-handshake libxml2: crafted xml can cause global buffer overflow nodejs-ip: arbitrary code execution via the isPublic() function sudo: Targeted Cor…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:1383"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-43646</id>
    <title>UBUNTU-CVE-2023-43646</title>
    <updated>2026-10-04T11:24:00.342886+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: node-get-func-name, Ubuntu:20.04:LTS: node-get-func-name, Ubuntu:22.04:LTS: node-get-func-name, Ubuntu:22.04:LTS: qt6-webengine, Ubuntu:24.04:LTS: node-get-func-name, Ubuntu:24.04:LTS: qt6-webengine, Ubuntu:25.10: node-get-func-name, Ubuntu:25.10: qt6-webengine, Ubuntu:26.04:LTS: node-get-func-name, Ubuntu:26.04:LTS: qt6-webengine</p>
<p>get-func-name is a module to retrieve a function's name securely and consistently both in NodeJS and the browser. Versions prior to 2.0.1 are subject to a regular expression denial of service (redos) vulnerability which may lead to a denial of service when parsing malicious input. This vulnerability can be exploited when there is an imbalance in parentheses, which results in excessive backtracking and subsequently increases the CPU load and processing time significantly. This vulnerability can be triggered using the following input: '\t'.repeat(54773) + '\t/function/i'. This issue has been addressed in commit `f934b228b` which has been included in releases from 2.0.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-43646"/>
  </entry>
</feed>
