<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T04:25:19.873309+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2024:5814</id>
    <title>ALSA-2024:5814 — Moderate: nodejs:20 security update</title>
    <updated>2026-10-03T04:25:20.242730+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: nodejs, AlmaLinux:8: nodejs-devel, AlmaLinux:8: nodejs-docs, AlmaLinux:8: nodejs-full-i18n, AlmaLinux:8: nodejs-nodemon, AlmaLinux:8: nodejs-packaging, AlmaLinux:8: nodejs-packaging-bundler, AlmaLinux:8: npm</p>
<p>Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.</p>
<p>Security Fix(es):</p>
<p>* node-tar: denial of service while parsing a tar file due to lack of folders depth validation (CVE-2024-28863)
* nodejs: Bypass network import restriction via data URL (CVE-2024-22020)
* nodejs: fs.lstat bypasses permission model (CVE-2024-22018)
* nodejs: fs.fchown/fchmod bypasses permission model (CVE-2024-36137)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2024:5814"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-09418</id>
    <title>bdu:2024-09418</title>
    <updated>2026-10-03T04:25:20.242820+00:00</updated>
    <content>bdu:2024-09418</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-09418"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0579</id>
    <title>certfr-2024-avi-0579 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T04:25:20.242839+00:00</updated>
    <content>certfr-2024-avi-0579</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0579"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-217372</id>
    <title>EUVD-2026-217372</title>
    <updated>2026-10-03T04:25:20.242857+00:00</updated>
    <content>EUVD-2026-217372</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-217372"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-28863</id>
    <title>fkie_cve-2024-28863</title>
    <updated>2026-10-03T04:25:20.242868+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no limit on the number of sub-folders created in the folder creation process. An attacker who generates a large number of sub-folders can consume memory on the system running node-tar and even crash the Node.js client within few seconds of running it using a path with too many sub-folders inside. Version 6.2.1 fixes this issue by preventing extraction in excessively deep sub-folders.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-28863"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-f5x3-32g6-xq36</id>
    <title>GHSA-f5x3-32g6-xq36 — Denial of service while parsing a tar file due to lack of folders count validation</title>
    <updated>2026-10-03T04:25:20.242892+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: node-tar, npm: tar</p>
<p>## Description: 
During some analysis today on npm's `node-tar` package I came across the folder creation process, Basicly if you provide node-tar with a path like this `./a/b/c/foo.txt` it would create every folder and sub-folder here a, b and c until it reaches the last folder to create `foo.txt`, In-this case I noticed that there's no validation at all on the amount of folders being created, that said we're actually able to CPU and memory consume the system running node-tar and even crash the nodejs client within few seconds of running it using a path with too many sub-folders inside</p>
<p>## Steps To Reproduce:
You can reproduce this issue by downloading the tar file I provided in the resources and using node-tar to extract it, you should get the same behavior as the video</p>
<p>## Proof Of Concept:
Here's a [video](https://hackerone-us-west-2-production-attachments.s3.us-west-2.amazonaws.com/3i7uojw8s52psar6pg8zkdo4h9io?response-content-disposition=attachment%3B%20filename%3D%22tar-dos-poc.webm%22%3B%20filename%2A%3DUTF-8%27%27tar-dos-poc.webm&amp;response-content-type=video%2Fwebm&amp;X-Amz-Algorithm=AWS4-HMAC-SHA256&amp;X-Amz-Credential=ASIAQGK6FURQSWWGDXHA%2F20240312%2Fus-west-2%2Fs3%2Faws4_request&amp;X-Amz-Date=20240312T080103Z&amp;X-Amz-Expires=3600&amp;X-Amz-Security-Token=IQoJb3JpZ2luX2VjEDcaCXVzLXdlc3QtMiJHMEUCID3xYDc6emXVPOg8iVR5dVk0u3gguTPIDJ0OIE%2BKxj17AiEAi%2BGiay1gGMWhH%2F031fvMYnSsa8U7CnpZpxvFAYqNRwgqsQUIQBADGgwwMTM2MTkyNzQ4NDkiDAaj6OgUL3gg4hhLLCqOBUUrOgWSqaK%2FmxN6nKRvB4Who3LIyzswFKm9LV9…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-f5x3-32g6-xq36"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-28863</id>
    <title>gsd-2024-28863</title>
    <updated>2026-10-03T04:25:20.242963+00:00</updated>
    <content>gsd-2024-28863</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-28863"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-28863</id>
    <title>msrc_CVE-2024-28863 — node-tar vulnerable to denial of service while parsing a tar file due to lack of folders count validation</title>
    <updated>2026-10-03T04:25:20.242977+00:00</updated>
    <content>msrc_CVE-2024-28863</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-28863"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2024:4924</id>
    <title>RHBA-2024:4924 — Red Hat Bug Fix Advisory: Red Hat Developer Hub 1.2.2 bugfix release</title>
    <updated>2026-10-03T04:25:20.242993+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>node-tar: denial of service while parsing a tar file due to lack of folders depth validation</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2024:4924"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:5814</id>
    <title>RHSA-2024:5814 — Red Hat Security Advisory: nodejs:20 security update</title>
    <updated>2026-10-03T04:25:20.243010+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>nodejs: fs.lstat bypasses permission model nodejs: Bypass network import restriction via data URL node-tar: denial of service while parsing a tar file due to lack of folders depth validation nodejs: fs.fchown/fchmod bypasses permission model</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:5814"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-28863</id>
    <title>UBUNTU-CVE-2024-28863</title>
    <updated>2026-10-03T04:25:20.243030+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:20.04:LTS: node-tar, Ubuntu:22.04:LTS: node-tar, Ubuntu:24.04:LTS: node-tar</p>
<p>node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no limit on the number of sub-folders created in the folder creation process. An attacker who generates a large number of sub-folders can consume memory on the system running node-tar and even crash the Node.js client within few seconds of running it using a path with too many sub-folders inside. Version 6.2.1 fixes this issue by preventing extraction in excessively deep sub-folders.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-28863"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1215</id>
    <title>WID-SEC-W-2024-1215 — IBM App Connect Enterprise: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-03T04:25:20.243054+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in IBM App Connect Enterprise ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1215"/>
  </entry>
</feed>
