<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T10:08:32.277362+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:7080</id>
    <title>ALSA-2026:7080 — Important: nodejs22 security update</title>
    <updated>2026-10-03T10:08:32.710520+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: nodejs-docs</p>
<p>Node.js is a platform built on Chrome's JavaScript runtime \ for easily building fast, scalable network applications. \ Node.js uses an event-driven, non-blocking I/O model that \ makes it lightweight and efficient, perfect for data-intensive \ real-time applications that run across distributed devices.</p>
<p>Security Fix(es):</p>
<p>* brace-expansion: brace-expansion: Denial of Service via unbounded brace range expansion (CVE-2026-25547)
  * minimatch: minimatch: Denial of Service via specially crafted glob patterns (CVE-2026-26996)
  * minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions (CVE-2026-27904)
  * undici: undici: Denial of Service via unbounded memory consumption during WebSocket permessage-deflate decompression (CVE-2026-1526)
  * undici: Undici: Denial of Service via invalid WebSocket permessage-deflate extension parameter (CVE-2026-2229)
  * undici: Undici: HTTP Request Smuggling and Denial of Service due to duplicate Content-Length headers (CVE-2026-1525)
  * undici: undici: Denial of Service via crafted WebSocket frame with large length (CVE-2026-1528)
  * nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination (CVE-2026-27135)
  * Node.js: Node.js: Denial of Service due to crafted HTTP `__proto__` header (CVE-2026-21710)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the Re…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:7080"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-1526</id>
    <title>BELL-CVE-2026-1526</title>
    <updated>2026-10-03T10:08:32.710655+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: nodejs, Alpaquita:25: nodejs, Alpaquita:stream: nodejs, BellSoft Hardened Containers:23: nodejs, BellSoft Hardened Containers:25: nodejs, BellSoft Hardened Containers:stream: nodejs</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-1526"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0500</id>
    <title>certfr-2026-avi-0500 — De multiples vulnérabilités ont été découvertes dans VMware Tanzu. Elles permettent à un attaquant de provoquer un prob…</title>
    <updated>2026-10-03T10:08:32.710715+00:00</updated>
    <content>certfr-2026-avi-0500</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0500"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ce10526</id>
    <title>Withdrawn: CLEANSTART-2026-CE10526 — Security fixes for CVE-2025-64756, CVE-2025-69873, CVE-2026-1525, CVE-2026-1526, CVE-2026-1527, CVE-2026-1528, CVE-2026…</title>
    <updated>2026-10-03T10:08:32.710735+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: renovate</p>
<p>Multiple security vulnerabilities affect the renovate package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ce10526"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-367740</id>
    <title>EUVD-2026-367740</title>
    <updated>2026-10-03T10:08:32.710765+00:00</updated>
    <content>EUVD-2026-367740</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-367740"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-1526</id>
    <title>fkie_cve-2026-1526</title>
    <updated>2026-10-03T10:08:32.710778+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessage-deflate decompression. When a WebSocket connection negotiates the permessage-deflate extension, the client decompresses incoming compressed frames without enforcing any limit on the decompressed data size. A malicious WebSocket server can send a small compressed frame (a "decompression bomb") that expands to an extremely large size in memory, causing the Node.js process to exhaust available memory and crash or become unresponsive.</p>
<p>The vulnerability exists in the PerMessageDeflate.decompress() method, which accumulates all decompressed chunks in memory and concatenates them into a single Buffer without checking whether the total size exceeds a safe threshold.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-1526"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vrm6-8vpv-qv8q</id>
    <title>GHSA-vrm6-8vpv-qv8q — Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression</title>
    <updated>2026-10-03T10:08:32.710807+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: undici</p>
<p>## Description</p>
<p>The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessage-deflate decompression. When a WebSocket connection negotiates the permessage-deflate extension, the client decompresses incoming compressed frames without enforcing any limit on the decompressed data size. A malicious WebSocket server can send a small compressed frame (a "decompression bomb") that expands to an extremely large size in memory, causing the Node.js process to exhaust available memory and crash or become unresponsive.</p>
<p>The vulnerability exists in the `PerMessageDeflate.decompress()` method, which accumulates all decompressed chunks in memory and concatenates them into a single Buffer without checking whether the total size exceeds a safe threshold.</p>
<p>## Impact</p>
<p>- Remote denial of service against any Node.js application using undici's WebSocket client
- A single compressed WebSocket frame of ~6 MB can decompress to ~1 GB or more
- Memory exhaustion occurs in native/external memory, bypassing V8 heap limits
- No application-level mitigation is possible as decompression occurs before message delivery</p>
<p>### Patches</p>
<p>Users should upgrade to fixed versions.</p>
<p>### Workarounds</p>
<p>No workaround are possible.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vrm6-8vpv-qv8q"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:13826</id>
    <title>RHSA-2026:13826 — Red Hat Security Advisory: Red Hat Developer Hub 1.9.4 release.</title>
    <updated>2026-10-03T10:08:32.710843+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization python-markdown: denial of service via malformed HTML-like sequences undici: Undici: HTTP Request Smuggling and Denial of Service due to duplicate Content-Length headers undici: undici: Denial of Service via unbounded memory consumption during WebSocket permessage-deflate decompression undici: undici: Denial of Service via crafted WebSocket frame with large length undici: Undici: Denial of Service via invalid WebSocket permessage-deflate extension parameter rhdh: GraphQL Injection Leading to Platform-Wide Denial of Service (DoS) in RH Developer Hub Orchestrator Plugin lodash: lodash: Arbitrary code execution via untrusted input in template imports path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressions Underscore.js: Underscore.js: Denial of Service via recursive data structures in flatten and isEqual functions minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution svgo: SVGO: Denial of Service via XML entity expansion backstage/plugin-techdocs-node: TechDocs Mkdocs configuration key enables arbitrary code execution flatted: flatted: Unbounded recursion DoS in parse() revive phase crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building golang: internal/syscall/unix: Root.Chmod can follow symlinks out…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:13826"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:7080</id>
    <title>RHSA-2026:7080 — Red Hat Security Advisory: nodejs22 security update</title>
    <updated>2026-10-03T10:08:32.710910+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>undici: Undici: HTTP Request Smuggling and Denial of Service due to duplicate Content-Length headers undici: undici: Denial of Service via unbounded memory consumption during WebSocket permessage-deflate decompression undici: undici: Denial of Service via crafted WebSocket frame with large length undici: Undici: Denial of Service via invalid WebSocket permessage-deflate extension parameter Node.js: Node.js: Denial of Service due to crafted HTTP `__proto__` header brace-expansion: brace-expansion: Denial of Service via unbounded brace range expansion minimatch: minimatch: Denial of Service via specially crafted glob patterns nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:7080"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-1526</id>
    <title>UBUNTU-CVE-2026-1526</title>
    <updated>2026-10-03T10:08:32.710946+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:24.04:LTS: node-undici, Ubuntu:25.10: node-undici, Ubuntu:26.04:LTS: node-undici</p>
<p>The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessage-deflate decompression. When a WebSocket connection negotiates the permessage-deflate extension, the client decompresses incoming compressed frames without enforcing any limit on the decompressed data size. A malicious WebSocket server can send a small compressed frame (a "decompression bomb") that expands to an extremely large size in memory, causing the Node.js process to exhaust available memory and crash or become unresponsive. The vulnerability exists in the PerMessageDeflate.decompress() method, which accumulates all decompressed chunks in memory and concatenates them into a single Buffer without checking whether the total size exceeds a safe threshold.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-1526"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0933</id>
    <title>WID-SEC-W-2026-0933 — IBM App Connect Enterprise (Hono und Undici): Mehrere Schwachstellen</title>
    <updated>2026-10-03T10:08:32.710976+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen oder andere nicht näher bezeichnete Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0933"/>
  </entry>
</feed>
