<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T18:41:34.337197+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:47057</id>
    <title>ALSA-2026:47057 — Important: nodejs:24 security update</title>
    <updated>2026-10-02T18:41:35.592560+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: nodejs, AlmaLinux:9: nodejs-devel, AlmaLinux:9: nodejs-docs, AlmaLinux:9: nodejs-full-i18n, AlmaLinux:9: nodejs-libs, AlmaLinux:9: nodejs-nodemon, AlmaLinux:9: nodejs-packaging, AlmaLinux:9: nodejs-packaging-bundler, AlmaLinux:9: npm, AlmaLinux:9: v8-13.6-devel</p>
<p>Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.</p>
<p>Security Fix(es):</p>
<p>* brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity (CVE-2026-13149)
  * tar: Node-tar: Denial of Service via malformed tar archive header (CVE-2026-59874)
  * tar: node-tar: Denial of Service via crafted gzip bomb (CVE-2026-59873)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:47057"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0958</id>
    <title>certfr-2026-avi-0958 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T18:41:35.592681+00:00</updated>
    <content>certfr-2026-avi-0958</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0958"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-cb11602</id>
    <title>Withdrawn: CLEANSTART-2026-CB11602 — Security fixes in npm 11.18.0-r0</title>
    <updated>2026-10-02T18:41:35.592703+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: npm</p>
<p>Package npm version 11.18.0-r0 fixes 1 vulnerabilities: CVE-2026-13149</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-cb11602"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-333805</id>
    <title>EUVD-2026-333805</title>
    <updated>2026-10-02T18:41:35.592725+00:00</updated>
    <content>EUVD-2026-333805</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-333805"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-13149</id>
    <title>fkie_cve-2026-13149</title>
    <updated>2026-10-02T18:41:35.592738+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-13149"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3jxr-9vmj-r5cp</id>
    <title>GHSA-3jxr-9vmj-r5cp — brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups</title>
    <updated>2026-10-02T18:41:35.592762+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: brace-expansion</p>
<p>### Summary
brace-expansion's expand() exhibits exponential-time - O(2ⁿ) - behavior in the number of consecutive non-expanding {} groups. A short, all-ASCII input (~90 bytes/30 groups) blocks the calling thread for minutes; a slightly longer input hangs it effectively indefinitely. Because the dominant consumers run on Node's single-threaded event loop, one small input can fully stall a worker/process.</p>
<p>In `expand_`, `post` is computed unconditionally at the top of the function, before the early-return branches that don't use it:
```js
const post = m.post.length ? expand_(m.post, max, false) : [''];   // always recurses
  ...
if (!isSequence &amp;&amp; !isOptions) {
  if (m.post.match(/,(?!,).*\}/)) {
    str = m.pre + '{' + m.body + escClose + m.post;
    return expand_(str, max, true); // restart — `post` discarded
  }
  return [str];
}
```</p>
<p>For input like a{},{},…, the first {} is non-expanding, so control reaches the {a},b} rewrite branch - but `expand_` has already recursed into post over the entire remaining tail, only to throw the result away.
Each level therefore spawns two recursive expansions over essentially the same remaining work: `T(n) = 2·T(n−1) ⇒ O(2ⁿ)`.</p>
<p>The max option does not mitigate this: max only bounds the output-building loops; neither the post recursion nor the rewrite recursion consults it.
  
Measured on 5.0.6:</p>
<p>| groups (n) | input bytes | time |
|---|---|---|
| 20 | 60 | 130 ms |
| 24 | 72 | 1.9 s |
| 26 | 78 | 7.8 s |
| 30 (PoC) | 90 | ~2 min |</p>
<p>### Pro…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3jxr-9vmj-r5cp"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0325</id>
    <title>NCSC-2026-0325 — Kwetsbaarheden verholpen in Atlassian producten</title>
    <updated>2026-10-02T18:41:35.592811+00:00</updated>
    <content>NCSC-2026-0325</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0325"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11220-1</id>
    <title>openSUSE-SU-2026:11220-1 — python313-pytest-html-4.2.0-4.1 on GA media</title>
    <updated>2026-10-02T18:41:35.592919+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python313-pytest-html-4.2.0-4.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11220-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:33866</id>
    <title>RHSA-2026:33866 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
    <updated>2026-10-02T18:41:35.592937+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity nodejs: Node.js: Denial of Service via unlimited HTTP/2 ORIGIN frames Node.js: Node.js: Trust-policy bypass due to hostname matching inconsistency nodejs: Node.js: Silent authority rebinding due to embedded-nul hostnames in TLS handling nodejs: Node.js: Certification validation bypass in TLS host verification nodejs: Node.js: Unauthorized file metadata modification nodejs: Node.js: Local server can be started without network permission via Permission API flaw js-yaml: js-yaml: Denial of Service via crafted YAML merge keys js-yaml: js-yaml: Denial of Service via quadratic CPU time parsing with merge keys js-yaml: js-yaml: Denial of Service via crafted YAML ordered-map document</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:33866"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:47057</id>
    <title>RLSA-2026:47057 — Important: nodejs:24 security update</title>
    <updated>2026-10-02T18:41:35.592968+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: nodejs, Rocky Linux:9: nodejs-nodemon, Rocky Linux:9: nodejs-packaging</p>
<p>Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.</p>
<p>Security Fix(es):</p>
<p>* brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity (CVE-2026-13149)</p>
<p>* tar: Node-tar: Denial of Service via malformed tar archive header (CVE-2026-59874)</p>
<p>* tar: node-tar: Denial of Service via crafted gzip bomb (CVE-2026-59873)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:47057"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:3713-1</id>
    <title>SUSE-SU-2026:3713-1 — Security update for Multi-Linux Manager Client Tools - Monitoring stack</title>
    <updated>2026-10-02T18:41:35.592997+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for Multi-Linux Manager Client Tools - Monitoring stack</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:3713-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-13149</id>
    <title>UBUNTU-CVE-2026-13149</title>
    <updated>2026-10-02T18:41:35.593016+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: node-brace-expansion, Ubuntu:20.04:LTS: node-brace-expansion, Ubuntu:22.04:LTS: node-brace-expansion, Ubuntu:24.04:LTS: node-brace-expansion, Ubuntu:25.10: node-brace-expansion, Ubuntu:26.04:LTS: node-brace-expansion</p>
<p>brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-13149"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2452</id>
    <title>WID-SEC-W-2026-2452 — Red Hat Ansible Automation Platform (node-tar, linkify-it, protobufjs, brace-expansion, fast-uri, DOMPurify): Mehrere S…</title>
    <updated>2026-10-02T18:41:35.593043+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu manipulieren, einen Denial-of-Service-Zustand auszulösen oder beliebigen Code auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2452"/>
  </entry>
</feed>
