<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T19:54:30.567047+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-05779</id>
    <title>bdu:2024-05779</title>
    <updated>2026-10-03T19:54:30.849796+00:00</updated>
    <content>bdu:2024-05779</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-05779"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0514</id>
    <title>certfr-2024-avi-0514 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T19:54:30.849841+00:00</updated>
    <content>certfr-2024-avi-0514</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0514"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-4600</id>
    <title>EUVD-2026-4600</title>
    <updated>2026-10-03T19:54:30.849861+00:00</updated>
    <content>EUVD-2026-4600</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-4600"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-29041</id>
    <title>fkie_cve-2024-29041</title>
    <updated>2026-10-03T19:54:30.849873+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Express.js minimalist web framework for node. Versions of Express.js prior to 4.19.0 and all pre-release alpha and beta versions of 5.0 are affected by an open redirect vulnerability using malformed URLs. When a user of Express performs a redirect using a user-provided URL Express performs an encode [using `encodeurl`](https://github.com/pillarjs/encodeurl) on the contents before passing it to the `location` header. This can cause malformed URLs to be evaluated in unexpected ways by common redirect allow list implementations in Express applications, leading to an Open Redirect via bypass of a properly implemented allow list. The main method impacted is `res.location()` but this is also called from within `res.redirect()`. The vulnerability is fixed in 4.19.2 and 5.0.0-beta.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-29041"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rv95-896h-c2vc</id>
    <title>GHSA-rv95-896h-c2vc — Express.js Open Redirect in malformed URLs</title>
    <updated>2026-10-03T19:54:30.849903+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: express</p>
<p>### Impact</p>
<p>Versions of Express.js prior to 4.19.2 and pre-release alpha and beta versions before 5.0.0-beta.3 are affected by an open redirect vulnerability using malformed URLs.</p>
<p>When a user of Express performs a redirect using a user-provided URL Express performs an encode [using `encodeurl`](https://github.com/pillarjs/encodeurl) on the contents before passing it to the `location` header. This can cause malformed URLs to be evaluated in unexpected ways by common redirect allow list implementations in Express applications, leading to an Open Redirect via bypass of a properly implemented allow list.</p>
<p>The main method impacted is `res.location()` but this is also called from within `res.redirect()`.</p>
<p>### Patches</p>
<p>https://github.com/expressjs/express/commit/0867302ddbde0e9463d0564fea5861feb708c2dd
https://github.com/expressjs/express/commit/0b746953c4bd8e377123527db11f9cd866e39f94</p>
<p>An initial fix went out with `express@4.19.0`, we then patched a feature regression in `4.19.1` and added improved handling for the bypass in `4.19.2`.</p>
<p>### Workarounds</p>
<p>The fix for this involves pre-parsing the url string with either `require('node:url').parse` or `new URL`. These are steps you can take on your own before passing the user input string to `res.location` or `res.redirect`.</p>
<p>### Resources</p>
<p>https://github.com/expressjs/express/pull/5539
https://github.com/koajs/koa/issues/1800
https://expressjs.com/en/4x/api.html#res.location</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rv95-896h-c2vc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-29041</id>
    <title>gsd-2024-29041</title>
    <updated>2026-10-03T19:54:30.849942+00:00</updated>
    <content>gsd-2024-29041</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-29041"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-29041</id>
    <title>msrc_CVE-2024-29041 — Express.js Open Redirect in malformed URLs</title>
    <updated>2026-10-03T19:54:30.849955+00:00</updated>
    <content>msrc_CVE-2024-29041</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-29041"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhea-2024:7870</id>
    <title>RHEA-2024:7870 — Red Hat Enhancement Advisory: Red Hat OpenShift Pipelines Operator Bundle 1.16.0 release</title>
    <updated>2026-10-03T19:54:30.849970+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>node-tar: denial of service while parsing a tar file due to lack of folders depth validation express: cause malformed URLs to be evaluated webpack-dev-middleware: lack of URL validation may lead to file leak axios: axios: Server-Side Request Forgery</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhea-2024:7870"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-29041</id>
    <title>UBUNTU-CVE-2024-29041</title>
    <updated>2026-10-03T19:54:30.849992+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: node-express, Ubuntu:Pro:18.04:LTS: node-express, Ubuntu:Pro:20.04:LTS: node-express, Ubuntu:Pro:22.04:LTS: node-express</p>
<p>Express.js minimalist web framework for node. Versions of Express.js prior to 4.19.0 and all pre-release alpha and beta versions of 5.0 are affected by an open redirect vulnerability using malformed URLs. When a user of Express performs a redirect using a user-provided URL Express performs an encode [using `encodeurl`](https://github.com/pillarjs/encodeurl) on the contents before passing it to the `location` header. This can cause malformed URLs to be evaluated in unexpected ways by common redirect allow list implementations in Express applications, leading to an Open Redirect via bypass of a properly implemented allow list. The main method impacted is `res.location()` but this is also called from within `res.redirect()`. The vulnerability is fixed in 4.19.2 and 5.0.0-beta.3.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-29041"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0956</id>
    <title>WID-SEC-W-2024-0956 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
    <updated>2026-10-03T19:54:30.850019+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Phishing-Angriffe durchzuführen, Sicherheitsmaßnahmen zu umgehen oder vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0956"/>
  </entry>
</feed>
