<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:26:05.058024+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-15402</id>
    <title>bdu:2025-15402</title>
    <updated>2026-10-02T14:26:05.827464+00:00</updated>
    <content>bdu:2025-15402</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-15402"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-1064</id>
    <title>certfr-2025-avi-1064 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-02T14:26:05.827555+00:00</updated>
    <content>certfr-2025-avi-1064</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-1064"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ui22412</id>
    <title>CLEANSTART-2026-UI22412 — Security fix for CVE-2025-12816 applied in: argo-workflows 3.6.19-r7, argo-workflows 3.7.15-r3</title>
    <updated>2026-10-02T14:26:05.827590+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: argo-workflows</p>
<p>CVE-2025-12816 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ui22412"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-261907</id>
    <title>EUVD-2026-261907</title>
    <updated>2026-10-02T14:26:05.827638+00:00</updated>
    <content>EUVD-2026-261907</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-261907"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-12816</id>
    <title>fkie_cve-2025-12816</title>
    <updated>2026-10-02T14:26:05.827666+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1 structures to desynchronize schema validations, yielding a semantic divergence that may bypass downstream cryptographic verifications and security decisions.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-12816"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5gfm-wpxj-wjgq</id>
    <title>GHSA-5gfm-wpxj-wjgq — node-forge has an Interpretation Conflict vulnerability via its ASN.1 Validator Desynchronization</title>
    <updated>2026-10-02T14:26:05.827706+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: node-forge</p>
<p>### Summary</p>
<p>CVE-2025-12816 has been reserved by CERT/CC</p>
<p>**Description**
An Interpretation Conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft ASN.1 structures to desynchronize schema validations, yielding a semantic divergence that may bypass downstream cryptographic verifications and security decisions.</p>
<p>### Details</p>
<p>A critical ASN.1 validation bypass vulnerability exists in the node-forge asn1.validate function within `forge/lib/asn1.js`. ASN.1 is a schema language that defines data structures, like the typed record schemas used in X.509, PKCS#7, PKCS#12, etc. DER (Distinguished Encoding Rules), a strict binary encoding of ASN.1, is what cryptographic code expects when verifying signatures, and the exact bytes and structure must match the schema used to compute and verify the signature. After deserializing DER, Forge uses static ASN.1 validation schemas to locate the signed data or public key, compute digests over the exact bytes required, and feed digest and signature fields into cryptographic primitives.</p>
<p>This vulnerability allows a specially crafted ASN.1 object to desynchronize the validator on optional boundaries, causing a malformed optional field to be semantically reinterpreted as the subsequent mandatory structure. This manifests as logic bypasses in cryptographic algorithms and protocols with optional security features (such as PKCS#12, where MACs are treated as absent) and semantic interpr…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5gfm-wpxj-wjgq"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-26-071-03</id>
    <title>ICSA-26-071-03 — Siemens SIDIS Prime</title>
    <updated>2026-10-02T14:26:05.827771+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters. An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing. An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key. Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key. There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above. Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-26-071-03"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-12816</id>
    <title>msrc_CVE-2025-12816 — CVE-2025-12816</title>
    <updated>2026-10-02T14:26:05.828052+00:00</updated>
    <content>msrc_CVE-2025-12816</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-12816"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0079</id>
    <title>NCSC-2026-0079 — Kwetsbaarheden verholpen in Siemens producten</title>
    <updated>2026-10-02T14:26:05.828082+00:00</updated>
    <content>NCSC-2026-0079</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0079"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:20177-1</id>
    <title>openSUSE-SU-2026:20177-1 — Security update for golang-github-prometheus-prometheus</title>
    <updated>2026-10-02T14:26:05.828194+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for golang-github-prometheus-prometheus</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:20177-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:22936</id>
    <title>RHSA-2025:22936 — Red Hat Security Advisory: Kiali 1.73.25 for Red Hat OpenShift Service Mesh 2.6</title>
    <updated>2026-10-02T14:26:05.828224+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications glob: glob: Command Injection Vulnerability via Malicious Filenames node-forge: node-forge ASN.1 Unbounded Recursion</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:22936"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-485750</id>
    <title>SSA-485750 — SSA-485750: Multiple Vulnerabilities in SIDIS Prime Before V4.0.800</title>
    <updated>2026-10-02T14:26:05.828260+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters. An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing. An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key. Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key. There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above. Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-485750"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:0628-1</id>
    <title>SUSE-SU-2026:0628-1 — Security update 5.1.2 for Multi-Linux Manager Client Tools</title>
    <updated>2026-10-02T14:26:05.828460+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update 5.1.2 for Multi-Linux Manager Client Tools</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:0628-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-12816</id>
    <title>UBUNTU-CVE-2025-12816</title>
    <updated>2026-10-02T14:26:05.828493+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:20.04:LTS: node-node-forge, Ubuntu:22.04:LTS: node-node-forge</p>
<p>An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1 structures to desynchronize schema validations, yielding a semantic divergence that may bypass downstream cryptographic verifications and security decisions.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-12816"/>
  </entry>
</feed>
