<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T13:39:40.512914+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-01715</id>
    <title>bdu:2026-01715</title>
    <updated>2026-10-02T13:39:40.557790+00:00</updated>
    <content>bdu:2026-01715</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-01715"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0651</id>
    <title>certfr-2025-avi-0651 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T13:39:40.557850+00:00</updated>
    <content>certfr-2025-avi-0651</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0651"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-iz17087</id>
    <title>CLEANSTART-2026-IZ17087 — Security fix for CVE-2025-5889 applied in: argo-workflows 3.6.19-r7</title>
    <updated>2026-10-02T13:39:40.557888+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: argo-workflows</p>
<p>Security vulnerability affects the argo-workflows package. This issue is resolved in later releases. See references for vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-iz17087"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-243757</id>
    <title>EUVD-2026-243757</title>
    <updated>2026-10-02T13:39:40.557935+00:00</updated>
    <content>EUVD-2026-243757</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-243757"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-5889</id>
    <title>fkie_cve-2025-5889</title>
    <updated>2026-10-02T13:39:40.557950+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability was found in juliangruber brace-expansion up to 1.1.11/2.0.1/3.0.0/4.0.0. It has been rated as problematic. Affected by this issue is the function expand of the file index.js. The manipulation leads to inefficient regular expression complexity. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 1.1.12, 2.0.2, 3.0.1 and 4.0.1 is able to address this issue. The name of the patch is a5b98a4f30d7813266b221435e1eaaf25a1b0ac5. It is recommended to upgrade the affected component.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-5889"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-v6h2-p8h4-qcjw</id>
    <title>GHSA-v6h2-p8h4-qcjw — brace-expansion Regular Expression Denial of Service vulnerability</title>
    <updated>2026-10-02T13:39:40.557975+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: brace-expansion</p>
<p>A vulnerability was found in juliangruber brace-expansion up to 1.1.11/2.0.1/3.0.0/4.0.0. It has been rated as problematic. Affected by this issue is the function expand of the file index.js. The manipulation leads to inefficient regular expression complexity. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 1.1.12, 2.0.2, 3.0.1 and 4.0.1 is able to address this issue. The name of the patch is `a5b98a4f30d7813266b221435e1eaaf25a1b0ac5`. It is recommended to upgrade the affected component.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-v6h2-p8h4-qcjw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-5889</id>
    <title>msrc_CVE-2025-5889 — juliangruber brace-expansion index.js expand redos</title>
    <updated>2026-10-02T13:39:40.558002+00:00</updated>
    <content>msrc_CVE-2025-5889</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-5889"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1645</id>
    <title>OESA-2025-1645 — nodejs-brace-expansion security update</title>
    <updated>2026-10-02T13:39:40.558019+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP3: nodejs-brace-expansion, openEuler:22.03-LTS-SP4: nodejs-brace-expansion, openEuler:24.03-LTS: nodejs-brace-expansion, openEuler:24.03-LTS-SP1: nodejs-brace-expansion, openEuler:20.03-LTS-SP4: nodejs-brace-expansion</p>
<p>Brace expansion as known from sh/bash

Security Fix(es):</p>
<p>A vulnerability was found in juliangruber brace-expansion up to 1.1.11/2.0.1/3.0.0/4.0.0. It has been rated as problematic. Affected by this issue is the function expand of the file index.js. The manipulation leads to inefficient regular expression complexity. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 1.1.12, 2.0.2, 3.0.1 and 4.0.1 is able to address this issue. The name of the patch is a5b98a4f30d7813266b221435e1eaaf25a1b0ac5. It is recommended to upgrade the affected component.(CVE-2025-5889)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1645"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15269-1</id>
    <title>openSUSE-SU-2025:15269-1 — jupyter-bqplot-jupyterlab-0.5.44-10.1 on GA media</title>
    <updated>2026-10-02T13:39:40.558050+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jupyter-bqplot-jupyterlab-0.5.44-10.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15269-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:21368</id>
    <title>RHSA-2025:21368 — Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.18 security, enhancement &amp; bug fix update</title>
    <updated>2026-10-02T13:39:40.558067+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>follow-redirects: Exposure of Private Personal Information to an Unauthorized Actor follow-redirects: Exposure of Sensitive Information via Authorization Header leak brace-expansion: juliangruber brace-expansion index.js expand redos operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd undici: Undici Uses Insufficiently Random Values</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:21368"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-5889</id>
    <title>UBUNTU-CVE-2025-5889</title>
    <updated>2026-10-02T13:39:40.558088+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: node-brace-expansion, Ubuntu:20.04:LTS: node-brace-expansion, Ubuntu:22.04:LTS: node-brace-expansion, Ubuntu:24.04:LTS: node-brace-expansion, Ubuntu:25.10: node-brace-expansion</p>
<p>A vulnerability was found in juliangruber brace-expansion up to 1.1.11/2.0.1/3.0.0/4.0.0. It has been rated as problematic. Affected by this issue is the function expand of the file index.js. The manipulation leads to inefficient regular expression complexity. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 1.1.12, 2.0.2, 3.0.1 and 4.0.1 is able to address this issue. The name of the patch is a5b98a4f30d7813266b221435e1eaaf25a1b0ac5. It is recommended to upgrade the affected component.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-5889"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2072</id>
    <title>WID-SEC-W-2025-2072 — IBM App Connect Enterprise: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-02T13:39:40.558114+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in IBM App Connect Enterprise ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2072"/>
  </entry>
</feed>
