<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:30:33.728386+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-09421</id>
    <title>bdu:2024-09421</title>
    <updated>2026-10-02T19:30:33.989168+00:00</updated>
    <content>bdu:2024-09421</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-09421"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0579</id>
    <title>certfr-2024-avi-0579 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T19:30:33.989214+00:00</updated>
    <content>certfr-2024-avi-0579</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0579"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-pi37875</id>
    <title>CLEANSTART-2026-PI37875 — Security fix for CVE-2024-4067 applied in: argo-workflows 3.6.19-r7, argo-workflows 3.7.15-r3, azure-functions-node 4.1…</title>
    <updated>2026-10-02T19:30:33.989234+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: argo-workflows, CleanStart: azure-functions-node</p>
<p>CVE-2024-4067 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-pi37875"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-186106</id>
    <title>EUVD-2026-186106</title>
    <updated>2026-10-02T19:30:33.989268+00:00</updated>
    <content>EUVD-2026-186106</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-186106"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-4067</id>
    <title>fkie_cve-2024-4067</title>
    <updated>2026-10-02T19:30:33.989281+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The NPM package `micromatch` prior to 4.0.8 is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerability occurs in `micromatch.braces()` in `index.js` because the pattern `.*` will greedily match anything. By passing a malicious payload, the pattern matching will keep backtracking to the input while it doesn't find the closing bracket. As the input size increases, the consumption time will also increase until it causes the application to hang or slow down. There was a merged fix but further testing shows the issue persists. This issue should be mitigated by using a safe pattern that won't start backtracking the regular expression due to greedy matching. This issue was fixed in version 4.0.8.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-4067"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-952p-6rrq-rcjv</id>
    <title>GHSA-952p-6rrq-rcjv — Regular Expression Denial of Service (ReDoS) in micromatch</title>
    <updated>2026-10-02T19:30:33.989307+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: micromatch</p>
<p>The NPM package `micromatch` prior to version 4.0.8 is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerability occurs in `micromatch.braces()` in `index.js` because the pattern `.*` will greedily match anything. By passing a malicious payload, the pattern matching will keep backtracking to the input while it doesn't find the closing bracket. As the input size increases, the consumption time will also increase until it causes the application to hang or slow down. There was a merged fix but further testing shows the issue persisted prior to https://github.com/micromatch/micromatch/pull/266. This issue should be mitigated by using a safe pattern that won't start backtracking the regular expression due to greedy matching.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-952p-6rrq-rcjv"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-4067</id>
    <title>gsd-2024-4067</title>
    <updated>2026-10-02T19:30:33.989332+00:00</updated>
    <content>gsd-2024-4067</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-4067"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14007-1</id>
    <title>openSUSE-SU-2024:14007-1 — jupyter-plotly-5.22.0-1.1 on GA media</title>
    <updated>2026-10-02T19:30:33.989343+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jupyter-plotly-5.22.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:14007-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2024:7523</id>
    <title>RHBA-2024:7523 — Red Hat Bug Fix Advisory: Red Hat Developer Hub 1.3.0 release</title>
    <updated>2026-10-02T19:30:33.989360+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>micromatch: vulnerable to Regular Expression Denial of Service braces: fails to limit the number of characters it can handle dset: Prototype Pollution golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses net/http: Denial of service due to improper 100-continue handling in net/http azure-identity: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/Azure/azure-sdk-for-go/sdk/azidentity urllib3: proxy-authorization request header is not stripped during cross-origin redirects fast-loops: prototype pollution via objectMergeDeep nodejs-async: Regular expression denial of service while parsing function in autoinject express: Improper Input Handling in Express Redirects serve-static: Improper Sanitization in serve-static</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2024:7523"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:3771-1</id>
    <title>SUSE-SU-2024:3771-1 — Security update for pgadmin4</title>
    <updated>2026-10-02T19:30:33.989390+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for pgadmin4</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:3771-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-4067</id>
    <title>UBUNTU-CVE-2024-4067</title>
    <updated>2026-10-02T19:30:33.989409+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: node-micromatch, Ubuntu:20.04:LTS: node-micromatch, Ubuntu:22.04:LTS: node-micromatch, Ubuntu:24.04:LTS: node-micromatch, Ubuntu:25.10: node-micromatch, Ubuntu:26.04:LTS: node-micromatch</p>
<p>The NPM package `micromatch` prior to 4.0.8 is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerability occurs in `micromatch.braces()` in `index.js` because the pattern `.*` will greedily match anything. By passing a malicious payload, the pattern matching will keep backtracking to the input while it doesn't find the closing bracket. As the input size increases, the consumption time will also increase until it causes the application to hang or slow down. There was a merged fix but further testing shows the issue persists. This issue should be mitigated by using a safe pattern that won't start backtracking the regular expression due to greedy matching. This issue was fixed in version 4.0.8.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-4067"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1566</id>
    <title>WID-SEC-W-2024-1566 — IBM QRadar SIEM: Mehrere Schwachstellen ermöglichen Denial of Service</title>
    <updated>2026-10-02T19:30:33.989439+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1566"/>
  </entry>
</feed>
