<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:55:17.704690+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-07454</id>
    <title>bdu:2025-07454</title>
    <updated>2026-10-02T14:55:17.954588+00:00</updated>
    <content>bdu:2025-07454</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-07454"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0724</id>
    <title>certfr-2025-avi-0724 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T14:55:17.954626+00:00</updated>
    <content>certfr-2025-avi-0724</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0724"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-268151</id>
    <title>EUVD-2026-268151</title>
    <updated>2026-10-02T14:55:17.954645+00:00</updated>
    <content>EUVD-2026-268151</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-268151"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-6547</id>
    <title>fkie_cve-2025-6547</title>
    <updated>2026-10-02T14:55:17.954657+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation.This issue affects pbkdf2: &lt;=3.1.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-6547"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-v62p-rq8g-8h59</id>
    <title>GHSA-v62p-rq8g-8h59 — pbkdf2 silently disregards Uint8Array input, returning static keys</title>
    <updated>2026-10-02T14:55:17.954685+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: pbkdf2</p>
<p>### Summary</p>
<p>On historic but declared as supported Node.js versions (0.12-2.x), pbkdf2 silently disregards Uint8Array input</p>
<p>This only affects Node.js &lt;3.0.0, but `pbkdf2` claims to:
 * Support Node.js [&gt;= 0.12](https://github.com/browserify/pbkdf2/blob/v3.1.2/package.json#L62) (and there seems to be ongoing effort in this repo to maintain that)
 * Support `Uint8Array` input (input is typechecked against Uint8Array, and the error message includes e.g. "Password must be a string, a Buffer, a typed array or a DataView"</p>
<p>### Details</p>
<p>The error is in `toBuffer` method</p>
<p>This vulnerability somehow even made it to tests: https://github.com/browserify/pbkdf2/commit/eb9f97a66ed83836bebc4ff563a1588248708501
There, `resultsOld` (where mismatch `results`) are just invalid output generated from empty password/salt instead of the supplied one</p>
<p>### PoC</p>
<p>On Node.js/io.js &lt; 3.0.0</p>
<p>```console
&gt; require('pbkdf2').pbkdf2Sync(new Uint8Array([1,2,3]), new Uint8Array([1,3,4]), 1024, 32, 'sha256')
&lt;Buffer 21 53 cd 5b a5 f0 15 39 2f 68 e2 40 8b 21 ba ca 0e dc 7b 20 d5 45 a4 8a ea b5 95 9f f0 be bf 66&gt;</p>
<p>// But that's just a hash of empty data with empty password:
&gt; require('pbkdf2').pbkdf2Sync('', '', 1024, 32, 'sha256')
&lt;Buffer 21 53 cd 5b a5 f0 15 39 2f 68 e2 40 8b 21 ba ca 0e dc 7b 20 d5 45 a4 8a ea b5 95 9f f0 be bf 66&gt;</p>
<p>// Node.js crypto is fine even on that version:
&gt; require('crypto').pbkdf2Sync(new Uint8Array([1,2,3]), new Uint8Array([1,3,4]), 1024, 32, 'sha256')
&lt;Buffer 78 10 cc 84 b7 bb 85…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-v62p-rq8g-8h59"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11126-1</id>
    <title>openSUSE-SU-2026:11126-1 — velociraptor-0.7.0.4.git185.a5708584-2.1 on GA media</title>
    <updated>2026-10-02T14:55:17.954736+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>velociraptor-0.7.0.4.git185.a5708584-2.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11126-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:10738</id>
    <title>RHSA-2025:10738 — Red Hat Security Advisory: Kiali 2.4.7 for Red Hat OpenShift Service Mesh 3.0</title>
    <updated>2026-10-02T14:55:17.954782+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>pbkdf2: pbkdf2 silently returns predictable key material pbkdf2: pbkdf2 silently returns static keys</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:10738"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-6547</id>
    <title>Withdrawn: UBUNTU-CVE-2025-6547</title>
    <updated>2026-10-02T14:55:17.954798+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> Ubuntu:18.04:LTS: node-pbkdf2, Ubuntu:20.04:LTS: node-pbkdf2, Ubuntu:22.04:LTS: node-pbkdf2, Ubuntu:24.04:LTS: node-pbkdf2, Ubuntu:25.10: node-pbkdf2, Ubuntu:26.04:LTS: node-pbkdf2</p>
<p>Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation.This issue affects pbkdf2: &lt;=3.1.2.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-6547"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1409</id>
    <title>WID-SEC-W-2025-1409 — IBM App Connect Enterprise: Mehrere Schwachstellen ermöglichen Manipulation von Daten</title>
    <updated>2026-10-02T14:55:17.954826+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Daten zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1409"/>
  </entry>
</feed>
