<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T22:35:16.650463+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-363389</id>
    <title>EUVD-2026-363389</title>
    <updated>2026-10-04T22:35:16.719105+00:00</updated>
    <content>EUVD-2026-363389</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-363389"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-71319</id>
    <title>fkie_cve-2025-71319</title>
    <updated>2026-10-04T22:35:16.719142+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF image parsers by providing a crafted image containing a box with a size of zero, causing the offset to never advance and permanently hanging the application.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-71319"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-m5qc-5hw7-8vg7</id>
    <title>GHSA-m5qc-5hw7-8vg7 — image-size Denial of Service via Infinite Loop during Image Processing</title>
    <updated>2026-10-04T22:35:16.719176+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: image-size</p>
<p>### Summary</p>
<p>`image-size` is vulnerable to a Denial of Service vulnerability when processing specially crafted images.</p>
<p>The issue occurs because of an infine loop in `findBox` when processing certain images with a box with size `0`.</p>
<p>### Details</p>
<p>If the first bytes of the input does not match any bytes in `firstBytes`, then the package tries to validate the image using other handlers:
```js
// https://github.com/image-size/image-size/blob/v1.2.0/lib/detector.ts#L20-L31
export function detector(input: Uint8Array): imageType | undefined {
  const byte = input[0]
  if (byte in firstBytes) {
    const type = firstBytes[byte]
    if (type &amp;&amp; typeHandlers[type].validate(input)) {
      return type
    }
  }</p>
<p>const finder = (key: imageType) =&gt; typeHandlers[key].validate(input) //&lt;--
  return keys.find(finder)
}
```</p>
<p>Some handlers that call `findBox` to validate or calculate the image size are `jxl`, `heif` and `jp2`.</p>
<p>`JXL` handler calls `findBox` inside `validate`. To reach the `findBox` call, the value at position `4:8` should be `'JXL '`
```js
// https://github.com/image-size/image-size/blob/v1.2.0/lib/types/jxl.ts#L51-L60
export const JXL: IImage = {
  validate: (input: Uint8Array): boolean =&gt; {
    const boxType = toUTF8String(input, 4, 8)
    if (boxType !== 'JXL ') return false      //&lt;---</p>
<p>const ftypBox = findBox(input, 'ftyp', 0) //&lt;---
    if (!ftypBox) return false</p>
<p>const brand = toUTF8String(input, ftypBox.offset + 8, ftypBox.offset + 12)
    return brand ===…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-m5qc-5hw7-8vg7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:33313</id>
    <title>RHSA-2026:33313 — Red Hat Security Advisory: A Subscription Management tool for finding and reporting Red Hat product usage</title>
    <updated>2026-10-04T22:35:16.719254+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libxml2: buffer over-read in xmlHTMLPrintFileContext in xmllint.c coreutils: Heap Buffer Under-Read in GNU Coreutils sort via Key Specification libxslt: use-after-free with key data stored cross-RVT libtasn1: libtasn1: Denial of Service via stack-based buffer overflow in asn1_expend_octet_string image-size: image-size: Denial of Service due to infinite loop when processing specially crafted images. python-pip: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite nginx: ngx_http_rewrite_module: code execution and denial of service openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key libpng: libpng: Arbitrary code execution due to use-after-free vulnerability libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion vim: Command injection allows arbitrary code execution via malicious tag files urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers urllib3: urllib3: Denial of Service due to excessive HTTP response decompression</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:33313"/>
  </entry>
</feed>
