<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T13:40:02.251032+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:35841</id>
    <title>ALSA-2026:35841 — Important: nodejs24 security, bug fix, and enhancement update</title>
    <updated>2026-10-02T13:40:02.896370+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: nodejs24, AlmaLinux:10: nodejs24-devel, AlmaLinux:10: nodejs24-docs, AlmaLinux:10: nodejs24-full-i18n, AlmaLinux:10: nodejs24-libs, AlmaLinux:10: nodejs24-npm</p>
<p>Node.js is a platform built on Chrome's JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices.</p>
<p>Security Fix(es):</p>
<p>* ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input (CVE-2026-42338)
  * undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (CVE-2026-12151)
  * undici: Undici: Information disclosure due to improper cache-control header parsing (CVE-2026-9678)
  * undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery. (CVE-2026-6733)
  * undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header (CVE-2026-11525)
  * undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy (CVE-2026-9697)
  * undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing (CVE-2026-6734)
  * nodejs: Node.js: Denial of Service via unlimited HTTP/2 ORIGIN frames (CVE-2026-48619)
  * nodejs: Node.js: Silent authority rebinding due to embedded-nul hostnames in TLS handling (CVE-2026-48930)
  * nodejs: Node.js: Unauthorized file metadata modification (CVE-2026-48935)
  * nodejs: Node.js WebCrypto: Denial of Service via large input to subtle.encrypt()…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:35841"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</id>
    <title>certfr-2026-avi-1094 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T13:40:02.896521+00:00</updated>
    <content>certfr-2026-avi-1094</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-cy92802</id>
    <title>CLEANSTART-2026-CY92802 — Security fix for CVE-2026-12151 applied in: npm 11.14.0-r4, npm 11.17.0-r1</title>
    <updated>2026-10-02T13:40:02.896546+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: npm</p>
<p>CVE-2026-12151 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-cy92802"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-366752</id>
    <title>EUVD-2026-366752</title>
    <updated>2026-10-02T13:40:02.896571+00:00</updated>
    <content>EUVD-2026-366752</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-366752"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-12151</id>
    <title>fkie_cve-2026-12151</title>
    <updated>2026-10-02T13:40:02.896584+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Impact:
The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and cumulative-size validation, collectively causing unbounded memory growth in the client process. The result is memory exhaustion and a denial of service.</p>
<p>Affected applications are those using the undici WebSocket client (new WebSocket(...)) or the WebSocketStream API that can be induced to connect to an attacker-controlled or compromised WebSocket endpoint.</p>
<p>All releases starting at undici 6.17.0 are affected.</p>
<p>Patches: Upgrade to undici &gt;= 6.26.0, &gt;= 7.28.0, or &gt;= 8.5.0. Workarounds:
No workaround is available. The fix must be applied through an upgrade.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-12151"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vxpw-j846-p89q</id>
    <title>GHSA-vxpw-j846-p89q — undici WebSocket client vulnerable to denial of service via fragment count bypass</title>
    <updated>2026-10-02T13:40:02.896616+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: undici</p>
<p>## Impact</p>
<p>The undici WebSocket client enforces `maxPayloadSize` on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and cumulative-size validation, collectively causing unbounded memory growth in the client process. The result is memory exhaustion and a denial of service.</p>
<p>Affected applications are those using the undici WebSocket client (`new WebSocket(...)`) or the `WebSocketStream` API that can be induced to connect to an attacker-controlled or compromised WebSocket endpoint.</p>
<p>All releases starting at undici 6.17.0 are affected.</p>
<p>## Patches</p>
<p>Upgrade to undici v6.27.0, v7.28.0 or v8.5.0.</p>
<p>## Workarounds</p>
<p>No workaround is available. The fix must be applied through an upgrade.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vxpw-j846-p89q"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0325</id>
    <title>NCSC-2026-0325 — Kwetsbaarheden verholpen in Atlassian producten</title>
    <updated>2026-10-02T13:40:02.896650+00:00</updated>
    <content>NCSC-2026-0325</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0325"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11121-1</id>
    <title>openSUSE-SU-2026:11121-1 — corepack24-24.17.0-1.1 on GA media</title>
    <updated>2026-10-02T13:40:02.896860+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>corepack24-24.17.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11121-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:34342</id>
    <title>RHSA-2026:34342 — Red Hat Security Advisory: Cluster Observability Operator 1.5.0</title>
    <updated>2026-10-02T13:40:02.896914+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>nodejs-trim: Regular Expression Denial of Service (ReDoS) in trim function nodejs-trim-newlines: ReDoS in .end() method braces: fails to limit the number of characters it can handle golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html launch-editor: vite: launch-editor: Arbitrary command execution via insufficient file argument sanitization golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2/jws golang.org/x/net/proxy: golang.org/x/net/http/httpproxy: HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net golang.org/x/net/html: Incorrect Neutralization of Input During Web Page Generation in x/net in golang.org/x/net golang.org/x/net/html: Quadratic parsing complexity in golang.org/x/net/html golang.org/x/net/html: Infinite parsing loop in golang.org/x/net undici: undici: Denial of Service via unbounded memory consumption during WebSocket permessage-deflate decompression undici: undici: Denial of Service via crafted WebSocket frame with large length undici: Undici: Denial of Service via invalid WebSocket permessage-deflate extension parameter lodash: lodash: Arbitrary code execution via untrusted input in template imports path-to-regexp: path-to-regexp: Denial of Service via catastrophic backtracking from malformed URL parameters fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies fast-uri: fast-uri: URI authority bypass due to improper delimiter handlin…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:34342"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:35841</id>
    <title>RLSA-2026:35841 — Important: nodejs24 security, bug fix, and enhancement update</title>
    <updated>2026-10-02T13:40:02.897045+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: nodejs24</p>
<p>Node.js is a platform built on Chrome's JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices.</p>
<p>Security Fix(es):</p>
<p>* ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input (CVE-2026-42338)</p>
<p>* undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (CVE-2026-12151)</p>
<p>* undici: Undici: Information disclosure due to improper cache-control header parsing (CVE-2026-9678)</p>
<p>* undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery. (CVE-2026-6733)</p>
<p>* undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header (CVE-2026-11525)</p>
<p>* undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy (CVE-2026-9697)</p>
<p>* undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing (CVE-2026-6734)</p>
<p>* nodejs: Node.js: Denial of Service via unlimited HTTP/2 ORIGIN frames (CVE-2026-48619)</p>
<p>* nodejs: Node.js: Silent authority rebinding due to embedded-nul hostnames in TLS handling (CVE-2026-48930)</p>
<p>* nodejs: Node.js: Unauthorized file metadata modification (CVE-2026-48935)</p>
<p>* nodejs: Node.js WebCrypto: Denial of Service via large input to subtle.encrypt() (CVE-2026-48933…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:35841"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22368-1</id>
    <title>SUSE-SU-2026:22368-1 — Security update for nodejs22</title>
    <updated>2026-10-02T13:40:02.897109+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for nodejs22</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22368-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-12151</id>
    <title>UBUNTU-CVE-2026-12151</title>
    <updated>2026-10-02T13:40:02.897166+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:24.04:LTS: node-undici, Ubuntu:25.10: node-undici, Ubuntu:26.04:LTS: node-undici</p>
<p>Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and cumulative-size validation, collectively causing unbounded memory growth in the client process. The result is memory exhaustion and a denial of service. Affected applications are those using the undici WebSocket client (new WebSocket(...)) or the WebSocketStream API that can be induced to connect to an attacker-controlled or compromised WebSocket endpoint. All releases starting at undici 6.17.0 are affected. Patches: Upgrade to undici &gt;= 6.26.0, &gt;= 7.28.0, or &gt;= 8.5.0. Workarounds: No workaround is available. The fix must be applied through an upgrade.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-12151"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2618</id>
    <title>WID-SEC-W-2026-2618 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
    <updated>2026-10-02T13:40:02.897218+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, und um Daten zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2618"/>
  </entry>
</feed>
