<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T06:32:39.579750+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0901</id>
    <title>certfr-2026-avi-0901 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-04T06:32:41.690712+00:00</updated>
    <content>certfr-2026-avi-0901</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0901"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ed19767</id>
    <title>Withdrawn: CLEANSTART-2026-ED19767 — Security fixes in opensearch-dashboards-fips 3.6.0-r4</title>
    <updated>2026-10-04T06:32:41.690824+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: opensearch-dashboards-fips</p>
<p>Package opensearch-dashboards-fips version 3.6.0-r4 fixes 7 vulnerabilities: ghsa-cmwh-pvxp-8882, CVE-2026-12143, CVE-2026-46625, CVE-2026-53550, CVE-2026-53655...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ed19767"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-366753</id>
    <title>EUVD-2026-366753</title>
    <updated>2026-10-04T06:32:41.690876+00:00</updated>
    <content>EUVD-2026-366753</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-366753"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-12143</id>
    <title>fkie_cve-2026-12143</title>
    <updated>2026-10-04T06:32:41.690906+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header without escaping carriage return (CR), line feed (LF), or double-quote (") characters. An application that passes attacker-controlled data as a field name or filename (for example, an API gateway that turns JSON object keys into multipart field names) allows the attacker to terminate the header line and inject additional headers, or to smuggle entire additional multipart parts, into the request the application forwards to a backend. This can let the attacker add or override form fields (e.g. set `is_admin=true`) seen by the downstream parser. This is an instance of CWE-93 (CRLF injection). The fix escapes CR, LF, and `"` as `%0D`, `%0A`, and `%22` in field names and filenames, matching the serialization browsers use per the WHATWG HTML multipart/form-data encoding algorithm. Exploitation requires the consuming application to use untrusted input as a field name or filename; applications that use only fixed/trusted field names are not affected. Fixed in 2.5.6, 3.0.5, and 4.0.6.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-12143"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hmw2-7cc7-3qxx</id>
    <title>GHSA-hmw2-7cc7-3qxx — form-data: CRLF injection in form-data via unescaped multipart field names and filenames</title>
    <updated>2026-10-04T06:32:41.690975+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: form-data</p>
<p>## Summary</p>
<p>`form-data` builds `multipart/form-data` request bodies. Through v4.0.5, the `field` name passed to `FormData#append` and the `filename` option are concatenated directly into the `Content-Disposition` header with no escaping of CR (`\r`), LF (`\n`), or `"`. An application that uses **untrusted input as a field name or filename** therefore lets an attacker terminate the header line and either inject additional headers or smuggle whole additional multipart parts into the request the application forwards to a backend.</p>
<p>This is CWE-93 (CRLF injection). It is a divergence from how browsers and the WHATWG HTML spec serialize form-data (they escape these characters), so the fix is to match that behavior. Severity is **conditional**: it depends on the consuming application passing attacker-controlled data as a field name or filename. Applications that only use fixed/trusted field names are not affected.</p>
<p>## Details</p>
<p>In `lib/form_data.js`, `_multiPartHeader` builds the part header as:</p>
<p>```javascript
'Content-Disposition': ['form-data', 'name="' + field + '"'].concat(contentDisposition || [])
```</p>
<p>and `_getContentDisposition` builds `filename="' + filename + '"'`. Neither escapes control characters, so a `\r\n` in `field`/`filename` ends the header line. The same applies to `"`, which can break out of the quoted parameter.</p>
<p>### Proof of concept</p>
<p>```javascript
const FormData = require('form-data');
const form = new FormData();
form.append('email"\r\nX-Injected: true\r\nfake…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hmw2-7cc7-3qxx"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-12143</id>
    <title>msrc_CVE-2026-12143 — form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)</title>
    <updated>2026-10-04T06:32:41.691120+00:00</updated>
    <content>msrc_CVE-2026-12143</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-12143"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0325</id>
    <title>NCSC-2026-0325 — Kwetsbaarheden verholpen in Atlassian producten</title>
    <updated>2026-10-04T06:32:41.691157+00:00</updated>
    <content>NCSC-2026-0325</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0325"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21448-1</id>
    <title>openSUSE-SU-2026:21448-1 — Security update for agama-web-ui</title>
    <updated>2026-10-04T06:32:41.691396+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for agama-web-ui</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:21448-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:33155</id>
    <title>RHSA-2026:33155 — Red Hat Security Advisory: Kiali 1.73.33 for Red Hat OpenShift Service Mesh 2.6</title>
    <updated>2026-10-04T06:32:41.691456+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>form-data: form-data: Form field override via CRLF injection golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input axios: Axios: Information disclosure of proxy credentials via HTTP redirects axios: Axios: Information disclosure of proxy credentials via redirect flows axios: Axios: Denial of Service due to unenforced request and response size limits axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution axios: Axios: Information disclosure due to prototype pollution vulnerability axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:33155"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-12143</id>
    <title>UBUNTU-CVE-2026-12143</title>
    <updated>2026-10-04T06:32:41.691528+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: node-form-data, Ubuntu:Pro:16.04:LTS: node-form-data, Ubuntu:Pro:18.04:LTS: node-form-data, Ubuntu:Pro:20.04:LTS: node-form-data, Ubuntu:Pro:22.04:LTS: node-form-data, Ubuntu:24.04:LTS: node-form-data, Ubuntu:25.10: node-form-data, Ubuntu:26.04:LTS: node-form-data</p>
<p>form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header without escaping carriage return (CR), line feed (LF), or double-quote (") characters. An application that passes attacker-controlled data as a field name or filename (for example, an API gateway that turns JSON object keys into multipart field names) allows the attacker to terminate the header line and inject additional headers, or to smuggle entire additional multipart parts, into the request the application forwards to a backend. This can let the attacker add or override form fields (e.g. set `is_admin=true`) seen by the downstream parser. This is an instance of CWE-93 (CRLF injection). The fix escapes CR, LF, and `"` as `%0D`, `%0A`, and `%22` in field names and filenames, matching the serialization browsers use per the WHATWG HTML multipart/form-data encoding algorithm. Exploitation requires the consuming application to use untrusted input as a field name or filename; applications that use only fixed/trusted field names are not affected. Fixed in 2.5.6, 3.0.5, and 4.0.6.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-12143"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2460</id>
    <title>WID-SEC-W-2026-2460 — Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management: Mehrere Schwachstellen</title>
    <updated>2026-10-04T06:32:41.691627+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2460"/>
  </entry>
</feed>
