<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:31:13.629114+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0923</id>
    <title>certfr-2024-avi-0923 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T19:31:13.803894+00:00</updated>
    <content>certfr-2024-avi-0923</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0923"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-dg43720</id>
    <title>CLEANSTART-2026-DG43720 — Security fix for CVE-2024-45296 applied in: argo-workflows 3.6.19-r6, argo-workflows 3.7.17-r1</title>
    <updated>2026-10-02T19:31:13.803975+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: argo-workflows</p>
<p>CVE-2024-45296 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-dg43720"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-211839</id>
    <title>EUVD-2026-211839</title>
    <updated>2026-10-02T19:31:13.804015+00:00</updated>
    <content>EUVD-2026-211839</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-211839"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-45296</id>
    <title>fkie_cve-2024-45296</title>
    <updated>2026-10-02T19:31:13.804029+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. Because JavaScript is single threaded and regex matching runs on the main thread, poor performance will block the event loop and lead to a DoS. The bad regular expression is generated any time you have two parameters within a single segment, separated by something that is not a period (.). For users of 0.1, upgrade to 0.1.10. All other users should upgrade to 8.0.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-45296"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9wv6-86v2-598j</id>
    <title>GHSA-9wv6-86v2-598j — path-to-regexp outputs backtracking regular expressions</title>
    <updated>2026-10-02T19:31:13.804054+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: path-to-regexp</p>
<p>### Impact</p>
<p>A bad regular expression is generated any time you have two parameters within a single segment, separated by something that is not a period (`.`). For example, `/:a-:b`.</p>
<p>### Patches</p>
<p>For users of 0.1, upgrade to `0.1.10`. All other users should upgrade to `8.0.0`.</p>
<p>These versions add backtrack protection when a custom regex pattern is not provided:</p>
<p>- [0.1.10](https://github.com/pillarjs/path-to-regexp/releases/tag/v0.1.10)
- [1.9.0](https://github.com/pillarjs/path-to-regexp/releases/tag/v1.9.0)
- [3.3.0](https://github.com/pillarjs/path-to-regexp/releases/tag/v3.3.0)
- [6.3.0](https://github.com/pillarjs/path-to-regexp/releases/tag/v6.3.0)</p>
<p>They do not protect against vulnerable user supplied capture groups. Protecting against explicit user patterns is out of scope for old versions and not considered a vulnerability.</p>
<p>Version [7.1.0](https://github.com/pillarjs/path-to-regexp/releases/tag/v7.1.0) can enable `strict: true` and get an error when the regular expression might be bad.</p>
<p>Version [8.0.0](https://github.com/pillarjs/path-to-regexp/releases/tag/v8.0.0) removes the features that can cause a ReDoS.</p>
<p>### Workarounds</p>
<p>All versions can be patched by providing a custom regular expression for parameters after the first in a single segment. As long as the custom regular expression does not match the text before the parameter, you will be safe. For example, change `/:a-:b` to `/:a-:b([^-/]+)`.</p>
<p>If paths cannot be rewritten and versions cannot be upgraded, anothe…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9wv6-86v2-598j"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-45296</id>
    <title>msrc_CVE-2024-45296 — path-to-regexp outputs backtracking regular expressions</title>
    <updated>2026-10-02T19:31:13.804104+00:00</updated>
    <content>msrc_CVE-2024-45296</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-45296"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0034</id>
    <title>NCSC-2026-0034 — Kwetsbaarheden verholpen in Atlassian producten</title>
    <updated>2026-10-02T19:31:13.804121+00:00</updated>
    <content>NCSC-2026-0034</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0034"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14374-1</id>
    <title>openSUSE-SU-2024:14374-1 — argocd-cli-2.12.4-1.1 on GA media</title>
    <updated>2026-10-02T19:31:13.804171+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>argocd-cli-2.12.4-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:14374-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2024:11265</id>
    <title>RHBA-2024:11265 — Red Hat Bug Fix Advisory: Red Hat Developer Hub 1.4.0 release.</title>
    <updated>2026-10-02T19:31:13.804188+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>http-proxy-middleware: http-proxy-middleware: Denial of Service via unhandled error during path matching cross-spawn: regular expression denial of service path-to-regexp: Backtracking regular expressions cause ReDoS body-parser: Denial of Service Vulnerability in body-parser plugin-catalog-backend: prototype pollution vulnerability plugin-techdocs-backend: storage bucket directory traversal in TechDocs plugin-techdocs-backend: circumvention of XSS protection in TechDocs backstage/plugin-app-backend: Unexpected visibility of environment variable configurations in @backstage/plugin-app-backend</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2024:11265"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-45296</id>
    <title>UBUNTU-CVE-2024-45296</title>
    <updated>2026-10-02T19:31:13.804215+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: node-path-to-regexp, Ubuntu:Pro:18.04:LTS: node-path-to-regexp, Ubuntu:Pro:20.04:LTS: node-path-to-regexp, Ubuntu:Pro:22.04:LTS: node-path-to-regexp, Ubuntu:Pro:24.04:LTS: node-path-to-regexp, Ubuntu:25.10: node-express, Ubuntu:26.04:LTS: node-express</p>
<p>path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. Because JavaScript is single threaded and regex matching runs on the main thread, poor performance will block the event loop and lead to a DoS. The bad regular expression is generated any time you have two parameters within a single segment, separated by something that is not a period (.). For users of 0.1, upgrade to 0.1.10. All other users should upgrade to 8.0.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-45296"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3211</id>
    <title>WID-SEC-W-2024-3211 — IBM App Connect Enterprise: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-02T19:31:13.804245+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in IBM App Connect Enterprise ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3211"/>
  </entry>
</feed>
