<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T13:26:01.468955+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:1351</id>
    <title>ALSA-2025:1351 — Important: nodejs:20 security update</title>
    <updated>2026-10-03T13:26:02.028532+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: nodejs, AlmaLinux:8: nodejs-devel, AlmaLinux:8: nodejs-docs, AlmaLinux:8: nodejs-full-i18n, AlmaLinux:8: nodejs-nodemon, AlmaLinux:8: nodejs-packaging, AlmaLinux:8: nodejs-packaging-bundler, AlmaLinux:8: npm</p>
<p>Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.</p>
<p>Security Fix(es):</p>
<p>* undici: Undici Uses Insufficiently Random Values (CVE-2025-22150)
  * nodejs: Node.js Worker Thread Exposure via Diagnostics Channel (CVE-2025-23083)
  * nodejs: GOAWAY HTTP/2 frames cause memory leak outside heap (CVE-2025-23085)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:1351"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-22150</id>
    <title>BELL-CVE-2025-22150</title>
    <updated>2026-10-03T13:26:02.028675+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: nodejs, Alpaquita:stream: nodejs, BellSoft Hardened Containers:23: nodejs, BellSoft Hardened Containers:stream: nodejs</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-22150"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0170</id>
    <title>certfr-2025-avi-0170 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T13:26:02.028725+00:00</updated>
    <content>certfr-2025-avi-0170</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0170"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-215265</id>
    <title>EUVD-2026-215265</title>
    <updated>2026-10-03T13:26:02.028755+00:00</updated>
    <content>EUVD-2026-215265</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-215265"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-22150</id>
    <title>fkie_cve-2025-22150</title>
    <updated>2026-10-03T13:26:02.028776+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Undici is an HTTP/1.1 client. Starting in version 4.5.0 and prior to versions 5.28.5, 6.21.1, and 7.2.3, undici uses `Math.random()` to choose the boundary for a multipart/form-data request. It is known that the output of `Math.random()` can be predicted if several of its generated values are known. If there is a mechanism in an app that sends multipart requests to an attacker-controlled website, they can use this to leak the necessary values. Therefore, an attacker can tamper with the requests going to the backend APIs if certain conditions are met. This is fixed in versions 5.28.5, 6.21.1, and 7.2.3. As a workaround, do not issue multipart requests to attacker controlled servers.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-22150"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-c76h-2ccp-4975</id>
    <title>GHSA-c76h-2ccp-4975 — Use of Insufficiently Random Values in undici</title>
    <updated>2026-10-03T13:26:02.028816+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: undici</p>
<p>### Impact</p>
<p>[Undici `fetch()` uses Math.random()](https://github.com/nodejs/undici/blob/8b06b8250907d92fead664b3368f1d2aa27c1f35/lib/web/fetch/body.js#L113) to choose the boundary for a multipart/form-data request. It is known that the output of Math.random() can be predicted if several of its generated values are known.</p>
<p>If there is a mechanism in an app that sends multipart requests to an attacker-controlled website, they can use this to leak the necessary values. Therefore, An attacker can tamper with the requests going to the backend APIs if certain conditions are met.</p>
<p>### Patches</p>
<p>This is fixed in 5.28.5; 6.21.1; 7.2.3.</p>
<p>### Workarounds</p>
<p>Do not issue multipart requests to attacker controlled servers.</p>
<p>### References</p>
<p>* https://hackerone.com/reports/2913312
* https://blog.securityevaluators.com/hacking-the-javascript-lottery-80cc437e3b7f</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-c76h-2ccp-4975"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-22150</id>
    <title>msrc_CVE-2025-22150 — Undici Uses Insufficiently Random Values</title>
    <updated>2026-10-03T13:26:02.028872+00:00</updated>
    <content>msrc_CVE-2025-22150</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-22150"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:14706-1</id>
    <title>openSUSE-SU-2025:14706-1 — corepack22-22.13.0-1.1 on GA media</title>
    <updated>2026-10-03T13:26:02.028902+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>corepack22-22.13.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:14706-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:17145</id>
    <title>RHSA-2025:17145 — Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.17 security, enhancement &amp; bug fix update</title>
    <updated>2026-10-03T13:26:02.028934+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>undici: Undici Uses Insufficiently Random Values</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:17145"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:0232-1</id>
    <title>SUSE-SU-2025:0232-1 — Security update for nodejs20</title>
    <updated>2026-10-03T13:26:02.028964+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for nodejs20</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:0232-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-22150</id>
    <title>UBUNTU-CVE-2025-22150</title>
    <updated>2026-10-03T13:26:02.028994+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:24.04:LTS: node-undici, Ubuntu:25.10: node-undici, Ubuntu:26.04:LTS: node-undici</p>
<p>Undici is an HTTP/1.1 client. Starting in version 4.5.0 and prior to versions 5.28.5, 6.21.1, and 7.2.3, undici uses `Math.random()` to choose the boundary for a multipart/form-data request. It is known that the output of `Math.random()` can be predicted if several of its generated values are known. If there is a mechanism in an app that sends multipart requests to an attacker-controlled website, they can use this to leak the necessary values. Therefore, an attacker can tamper with the requests going to the backend APIs if certain conditions are met. This is fixed in versions 5.28.5, 6.21.1, and 7.2.3. As a workaround, do not issue multipart requests to attacker controlled servers.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-22150"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0156</id>
    <title>WID-SEC-W-2025-0156 — Node.js: Mehrere Schwachstellen</title>
    <updated>2026-10-03T13:26:02.029037+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Node.js ausnutzen, um Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen preiszugeben, einen Denial-of-Service-Zustand herbeizuführen oder nicht näher spezifizierte Angriffe zu starten.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0156"/>
  </entry>
</feed>
