<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:04:52.727183+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0279</id>
    <title>certfr-2025-avi-0279 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T14:04:52.817904+00:00</updated>
    <content>certfr-2025-avi-0279</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0279"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ad27625</id>
    <title>Withdrawn: CLEANSTART-2026-AD27625 — Security fixes for CVE-2022-25881, CVE-2022-33987, CVE-2025-25285, CVE-2025-62718, CVE-2025-69873, CVE-2026-21637, CVE-…</title>
    <updated>2026-10-02T14:04:52.817943+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: mongosh</p>
<p>Multiple security vulnerabilities affect the mongosh package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ad27625"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-217757</id>
    <title>EUVD-2026-217757</title>
    <updated>2026-10-02T14:04:52.817979+00:00</updated>
    <content>EUVD-2026-217757</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-217757"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-25285</id>
    <title>fkie_cve-2025-25285</title>
    <updated>2026-10-02T14:04:52.817993+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>@octokit/endpoint turns REST API endpoints into generic request options. Starting in version 4.1.0 and prior to version 10.1.3, by crafting specific `options` parameters, the `endpoint.parse(options)` call can be triggered, leading to a regular expression denial-of-service (ReDoS) attack. This causes the program to hang and results in high CPU utilization. The issue occurs in the `parse` function within the `parse.ts` file of the npm package `@octokit/endpoint`. Version 10.1.3 contains a patch for the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-25285"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-x4c5-c7rf-jjgv</id>
    <title>GHSA-x4c5-c7rf-jjgv — @octokit/endpoint has a Regular Expression in parse that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking</title>
    <updated>2026-10-02T14:04:52.818016+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @octokit/endpoint</p>
<p>### Summary
By crafting specific `options` parameters, the `endpoint.parse(options)` call can be triggered, leading to a regular expression denial-of-service (ReDoS) attack. This causes the program to hang and results in high CPU utilization.</p>
<p>### Details
The issue occurs in the `parse` function within the `parse.ts` file of the npm package `@octokit/endpoint`. The specific code is located at the following link: https://github.com/octokit/endpoint.js/blob/main/src/parse.ts, at line 62:
```ts
headers.accept.match(/[\w-]+(?=-preview)/g) || ([] as string[]);
```
The regular expression `/[\w-]+(?=-preview)/g` encounters a backtracking issue when it processes `a large number of characters` followed by the `-` symbol.
e.g., the attack string: 
```js
"" + "A".repeat(100000) + "-"
```</p>
<p>### PoC
[The gist](https://gist.github.com/ShiyuBanzhou/a17202ac1ad403a80ca302466d5e56c4)
Here is the reproduction process for the vulnerability:
1. run `npm i @octokit/endpoint`
2. Move `poc.js` to the root directory of the same level as `README.md`
3. run `node poc.js`
result:
4. then the program will be stuck forever with high CPU usage
```js
import { endpoint } from "@octokit/endpoint";
// import { parse } from "./node_modules/@octokit/endpoint/dist-src/parse.js";
const options = {  
  method: "POST",
  url: "/graphql", // Ensure that the URL ends with "/graphql"
  headers: {
    accept: "" + "A".repeat(100000) + "-", // Pass in the attack string
    "content-type": "text/plain",
  },
  mediaType:…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-x4c5-c7rf-jjgv"/>
  </entry>
</feed>
