<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T10:28:21.074440+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0958</id>
    <title>certfr-2024-avi-0958 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T10:28:21.175975+00:00</updated>
    <content>certfr-2024-avi-0958</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0958"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-nq54168</id>
    <title>CLEANSTART-2026-NQ54168 — Security fix for CVE-2024-47764 applied in: argo-workflows 3.6.19-r7</title>
    <updated>2026-10-03T10:28:21.176023+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: argo-workflows</p>
<p>Security vulnerability affects the argo-workflows package. This issue is resolved in later releases. See references for vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-nq54168"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-193015</id>
    <title>EUVD-2026-193015</title>
    <updated>2026-10-03T10:28:21.176057+00:00</updated>
    <content>EUVD-2026-193015</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-193015"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-47764</id>
    <title>fkie_cve-2024-47764</title>
    <updated>2026-10-03T10:28:21.176071+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>cookie is a basic HTTP cookie parser and serializer for HTTP servers. The cookie name could be used to set other fields of the cookie, resulting in an unexpected cookie value. A similar escape can be used for path and domain, which could be abused to alter other fields of the cookie. Upgrade to 0.7.0, which updates the validation for name, path, and domain.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-47764"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-pxg6-pf52-xh8x</id>
    <title>GHSA-pxg6-pf52-xh8x — cookie accepts cookie name, path, and domain with out of bounds characters</title>
    <updated>2026-10-03T10:28:21.176094+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: cookie</p>
<p>### Impact</p>
<p>The cookie name could be used to set other fields of the cookie, resulting in an unexpected cookie value. For example, `serialize("userName=&lt;script&gt;alert('XSS3')&lt;/script&gt;; Max-Age=2592000; a", value)` would result in `"userName=&lt;script&gt;alert('XSS3')&lt;/script&gt;; Max-Age=2592000; a=test"`, setting `userName` cookie to `&lt;script&gt;` and ignoring `value`.</p>
<p>A similar escape can be used for `path` and `domain`, which could be abused to alter other fields of the cookie.</p>
<p>### Patches</p>
<p>Upgrade to 0.7.0, which updates the validation for `name`, `path`, and `domain`.</p>
<p>### Workarounds</p>
<p>Avoid passing untrusted or arbitrary values for these fields, ensure they are set by the application instead of user input.</p>
<p>### References</p>
<p>* https://github.com/jshttp/cookie/pull/167</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-pxg6-pf52-xh8x"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-47764</id>
    <title>msrc_CVE-2024-47764 — cookie accepts cookie name path and domain with out of bounds characters</title>
    <updated>2026-10-03T10:28:21.176125+00:00</updated>
    <content>msrc_CVE-2024-47764</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-47764"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-47764</id>
    <title>UBUNTU-CVE-2024-47764</title>
    <updated>2026-10-03T10:28:21.176143+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: node-cookie, Ubuntu:18.04:LTS: node-cookie, Ubuntu:20.04:LTS: node-cookie, Ubuntu:22.04:LTS: node-cookie, Ubuntu:24.04:LTS: node-cookie</p>
<p>cookie is a basic HTTP cookie parser and serializer for HTTP servers. The cookie name could be used to set other fields of the cookie, resulting in an unexpected cookie value. A similar escape can be used for path and domain, which could be abused to alter other fields of the cookie. Upgrade to 0.7.0, which updates the validation for name, path, and domain.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-47764"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0034</id>
    <title>WID-SEC-W-2025-0034 — IBM App Connect Enterprise: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
    <updated>2026-10-03T10:28:21.176168+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0034"/>
  </entry>
</feed>
