<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:31:32.880382+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:18480</id>
    <title>ALSA-2026:18480 — Important: linux-sgx security update</title>
    <updated>2026-10-02T19:31:32.978274+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: sgx-common, AlmaLinux:10: sgx-libs, AlmaLinux:10: sgx-mpa, AlmaLinux:10: sgx-pccs, AlmaLinux:10: sgx-pccs-admin, AlmaLinux:10: sgx-pckid-tool, AlmaLinux:10: tdx-qgs</p>
<p>The Intel SGX SDK is a collection of APIs, libraries, documentations and tools that allow software developers to create and debug Intel SGX enabled applications in C/C++.</p>
<p>Security Fix(es):</p>
<p>* qs: qs: Denial of Service via improper input validation in array parsing (CVE-2025-15284)
  * node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives (CVE-2026-23745)
  * node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition (CVE-2026-23950)
  * lodash: prototype pollution in _.unset and _.omit functions (CVE-2025-13465)
  * node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check (CVE-2026-24842)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:18480"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-00589</id>
    <title>bdu:2026-00589</title>
    <updated>2026-10-02T19:31:32.978353+00:00</updated>
    <content>bdu:2026-00589</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-00589"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0224</id>
    <title>certfr-2026-avi-0224 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T19:31:32.978371+00:00</updated>
    <content>certfr-2026-avi-0224</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0224"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ad27625</id>
    <title>Withdrawn: CLEANSTART-2026-AD27625 — Security fixes for CVE-2022-25881, CVE-2022-33987, CVE-2025-25285, CVE-2025-62718, CVE-2025-69873, CVE-2026-21637, CVE-…</title>
    <updated>2026-10-02T19:31:32.978387+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: mongosh</p>
<p>Multiple security vulnerabilities affect the mongosh package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ad27625"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-364304</id>
    <title>EUVD-2026-364304</title>
    <updated>2026-10-02T19:31:32.978413+00:00</updated>
    <content>EUVD-2026-364304</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-364304"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-23745</id>
    <title>fkie_cve-2026-23745</title>
    <updated>2026-10-02T19:31:32.978425+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>node-tar is a Tar for Node.js. The node-tar library (&lt;= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries when preservePaths is false (the default secure behavior). This allows malicious archives to bypass the extraction root restriction, leading to Arbitrary File Overwrite via hardlinks and Symlink Poisoning via absolute symlink targets. This vulnerability is fixed in 7.5.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-23745"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8qq5-rm4j-mr97</id>
    <title>GHSA-8qq5-rm4j-mr97 — node-tar is Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization</title>
    <updated>2026-10-02T19:31:32.978448+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: tar</p>
<p>### Summary</p>
<p>The `node-tar` library (`&lt;= 7.5.2`) fails to sanitize the `linkpath` of `Link` (hardlink) and `SymbolicLink` entries when `preservePaths` is false (the default secure behavior). This allows malicious archives to bypass the extraction root restriction, leading to **Arbitrary File Overwrite** via hardlinks and **Symlink Poisoning** via absolute symlink targets.</p>
<p>### Details</p>
<p>The vulnerability exists in `src/unpack.ts` within the `[HARDLINK]` and `[SYMLINK]` methods.</p>
<p>**1. Hardlink Escape (Arbitrary File Overwrite)**</p>
<p>The extraction logic uses `path.resolve(this.cwd, entry.linkpath)` to determine the hardlink target. Standard Node.js behavior dictates that if the second argument (`entry.linkpath`) is an **absolute path**, `path.resolve` ignores the first argument (`this.cwd`) entirely and returns the absolute path.</p>
<p>The library fails to validate that this resolved target remains within the extraction root. A malicious archive can create a hardlink to a sensitive file on the host (e.g., `/etc/passwd`) and subsequently write to it, if file permissions allow writing to the target file, bypassing path-based security measures that may be in place.</p>
<p>**2. Symlink Poisoning**</p>
<p>The extraction logic passes the user-supplied `entry.linkpath` directly to `fs.symlink` without validation. This allows the creation of symbolic links pointing to sensitive absolute system paths or traversing paths (`../../`), even when secure extraction defaults are used.</p>
<p>### PoC</p>
<p>The following scr…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8qq5-rm4j-mr97"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:18480</id>
    <title>RHSA-2026:18480 — Red Hat Security Advisory: linux-sgx security update</title>
    <updated>2026-10-02T19:31:32.978495+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>lodash: prototype pollution in _.unset and _.omit functions qs: qs: Denial of Service via improper input validation in array parsing node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:18480"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:19712</id>
    <title>RHSA-2026:19712 — Red Hat Security Advisory: RHOAI 3.3.3 - Red Hat OpenShift AI</title>
    <updated>2026-10-02T19:31:32.978522+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>vllm: Server Side request forgery (SSRF) in MediaConnector node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications lodash: prototype pollution in _.unset and _.omit functions qs: qs: Denial of Service via improper input validation in array parsing react-router: @remix-run/router: React Router XSS Vulnerability golang: net/url: Memory exhaustion in query parameter parsing in net/url crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate vllm: VLLM deserialization vulnerability leading to DoS and potential RCE axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization glob: glob: Command Injection Vulnerability via Malicious Filenames node-forge: node-forge ASN.1 Unbounded Recursion urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion vllm: vLLM: Remote Code Execution via malicious model configuration urllib3: urllib3 Streaming API improperly handles highly compressed data aiohttp: AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb ajv: ReDoS via $data reference nltk: NLTK: Arbitrary file read via improper path validation in `filestring()` function nltk: NLTK: Arbitrary file read via path traversal vulnerability lodash: lodash: Arbitrary code execution via untrusted input in template imports urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming A…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:19712"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:18480</id>
    <title>RLSA-2026:18480 — Important: linux-sgx security update</title>
    <updated>2026-10-02T19:31:32.978649+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: linux-sgx</p>
<p>The Intel SGX SDK is a collection of APIs, libraries, documentations and tools that allow software developers to create and debug Intel SGX enabled applications in C/C++.</p>
<p>Security Fix(es):</p>
<p>* qs: qs: Denial of Service via improper input validation in array parsing (CVE-2025-15284)</p>
<p>* node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives (CVE-2026-23745)</p>
<p>* node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition (CVE-2026-23950)</p>
<p>* lodash: prototype pollution in _.unset and _.omit functions (CVE-2025-13465)</p>
<p>* node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check (CVE-2026-24842)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the Rocky Linux 10 Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:18480"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-23745</id>
    <title>UBUNTU-CVE-2026-23745</title>
    <updated>2026-10-02T19:31:32.978680+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: node-tar, Ubuntu:Pro:16.04:LTS: node-tar, Ubuntu:18.04:LTS: node-tar, Ubuntu:Pro:20.04:LTS: node-tar, Ubuntu:22.04:LTS: node-tar, Ubuntu:24.04:LTS: node-tar, Ubuntu:25.10: node-tar, Ubuntu:26.04:LTS: node-tar</p>
<p>node-tar is a Tar for Node.js. The node-tar library (&lt;= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries when preservePaths is false (the default secure behavior). This allows malicious archives to bypass the extraction root restriction, leading to Arbitrary File Overwrite via hardlinks and Symlink Poisoning via absolute symlink targets. This vulnerability is fixed in 7.5.3.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-23745"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0770</id>
    <title>WID-SEC-W-2026-0770 — Atlassian Jira: Mehrere Schwachstellen</title>
    <updated>2026-10-02T19:31:32.978709+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Atlassian Jira ausnutzen, um beliebigen Programmcode auszuführen, Daten zu manipulieren und offenzulegen, Cross-Site-Scripting-Angriffe durchzuführen oder einen Denial-of-Service-Zustand herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0770"/>
  </entry>
</feed>
