<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T07:48:10.811417+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-15156</id>
    <title>bdu:2025-15156</title>
    <updated>2026-10-03T07:48:10.901447+00:00</updated>
    <content>bdu:2025-15156</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-15156"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-ale-014</id>
    <title>certfr-2025-ale-014 — **&lt;span class="important-content"&gt;[Mise à jour du 11 décembre 2025]&lt;/span&gt;**

Le CERT-FR a connaissance de multiples ex…</title>
    <updated>2026-10-03T07:48:10.901487+00:00</updated>
    <content>certfr-2025-ale-014</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-ale-014"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-1131</id>
    <title>certfr-2025-avi-1131 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T07:48:10.901514+00:00</updated>
    <content>certfr-2025-avi-1131</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-1131"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cisco-sa-react-flight-tyw32ddb</id>
    <title>cisco-sa-react-flight-TYw32Ddb — Remote Code Execution Vulnerability in React and Next.js Frameworks: December 2025</title>
    <updated>2026-10-03T07:48:10.901529+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>On December 3, 2025, the React team released a security advisory regarding a vulnerability, CVE-2025-55182, in the React server that could allow an unauthenticated, remote attacker to perform remote code execution on an affected device or system.

For a description of this vulnerability, see the public React Security Advisory ["https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components"].

Cisco's standard practice is to update integrated third-party software components to later versions as they become available.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cisco-sa-react-flight-tyw32ddb"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2025-29924</id>
    <title>cnvd-2025-29924</title>
    <updated>2026-10-03T07:48:10.901582+00:00</updated>
    <content>cnvd-2025-29924</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2025-29924"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-344008</id>
    <title>EUVD-2026-344008</title>
    <updated>2026-10-03T07:48:10.901610+00:00</updated>
    <content>EUVD-2026-344008</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-344008"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-55182</id>
    <title>fkie_cve-2025-55182</title>
    <updated>2026-10-03T07:48:10.901620+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-55182"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fv66-9v8q-g76r</id>
    <title>GHSA-fv66-9v8q-g76r — React Server Components are Vulnerable to RCE</title>
    <updated>2026-10-03T07:48:10.901642+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: react-server-dom-webpack, npm: react-server-dom-turbopack, npm: react-server-dom-parcel</p>
<p>### Impact</p>
<p>There is an unauthenticated remote code execution vulnerability in React Server Components.</p>
<p>We recommend upgrading immediately.</p>
<p>The vulnerability is present in versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 of:
* [react-server-dom-webpack](https://www.npmjs.com/package/react-server-dom-webpack)
* [react-server-dom-parcel](https://www.npmjs.com/package/react-server-dom-parcel)
* [react-server-dom-turbopack](https://www.npmjs.com/package/react-server-dom-turbopack?activeTab=readme)</p>
<p>### Patches</p>
<p>A fix was introduced in versions [19.0.1](https://github.com/facebook/react/releases/tag/v19.0.1), [19.1.2](https://github.com/facebook/react/releases/tag/v19.1.2), and [19.2.1](https://github.com/facebook/react/releases/tag/v19.2.1). If you are using any of the above packages please upgrade to any of the fixed versions immediately.</p>
<p>If your app’s React code does not use a server, your app is not affected by this vulnerability. If your app does not use a framework, bundler, or bundler plugin that supports React Server Components, your app is not affected by this vulnerability.</p>
<p>### References</p>
<p>See the [blog post](https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components) for more information and upgrade instructions.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fv66-9v8q-g76r"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2738</id>
    <title>WID-SEC-W-2025-2738 — Vercel Next.js und React Server Components (React2Shell): Schwachstelle ermöglicht Codeausführung</title>
    <updated>2026-10-03T07:48:10.901690+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Vercel Next.js und React ausnutzen, um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2738"/>
  </entry>
</feed>
