<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T11:12:14.770607+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:7350</id>
    <title>ALSA-2026:7350 — Important: nodejs:24 security update</title>
    <updated>2026-10-03T11:12:14.910379+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: nodejs, AlmaLinux:9: nodejs-devel, AlmaLinux:9: nodejs-docs, AlmaLinux:9: nodejs-full-i18n, AlmaLinux:9: nodejs-libs, AlmaLinux:9: nodejs-nodemon, AlmaLinux:9: nodejs-packaging, AlmaLinux:9: nodejs-packaging-bundler, AlmaLinux:9: npm, AlmaLinux:9: v8-13.6-devel</p>
<p>Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.</p>
<p>Security Fix(es):</p>
<p>* nodejs: Nodejs denial of service (CVE-2026-21637)
  * brace-expansion: brace-expansion: Denial of Service via unbounded brace range expansion (CVE-2026-25547)
  * minimatch: minimatch: Denial of Service via specially crafted glob patterns (CVE-2026-26996)
  * undici: Undici: Denial of Service due to uncontrolled resource consumption (CVE-2026-2581)
  * undici: Undici: HTTP header injection and request smuggling vulnerability (CVE-2026-1527)
  * undici: undici: Denial of Service via unbounded memory consumption during WebSocket permessage-deflate decompression (CVE-2026-1526)
  * undici: Undici: Denial of Service via invalid WebSocket permessage-deflate extension parameter (CVE-2026-2229)
  * undici: Undici: HTTP Request Smuggling and Denial of Service due to duplicate Content-Length headers (CVE-2026-1525)
  * undici: undici: Denial of Service via crafted WebSocket frame with large length (CVE-2026-1528)
  * nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination (CVE-2026-27135)
  * Node.js: Node.js: Denial of Service via malformed Internationalized Domain Name processing (CVE-2026-21712)
  * Node.js: Node.js: Denial of Service due to crafted HTTP `__proto__` header (CVE-2026-21710)
  * Node.js: Node.js: Information disclosure due to `fs.realpathSync.native()` bypassing filesyste…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:7350"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-2581</id>
    <title>BELL-CVE-2026-2581</title>
    <updated>2026-10-03T11:12:14.910473+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:stream: nodejs, BellSoft Hardened Containers:stream: nodejs</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-2581"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0667</id>
    <title>certfr-2026-avi-0667 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T11:12:14.910499+00:00</updated>
    <content>certfr-2026-avi-0667</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0667"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ce10526</id>
    <title>Withdrawn: CLEANSTART-2026-CE10526 — Security fixes for CVE-2025-64756, CVE-2025-69873, CVE-2026-1525, CVE-2026-1526, CVE-2026-1527, CVE-2026-1528, CVE-2026…</title>
    <updated>2026-10-03T11:12:14.910517+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: renovate</p>
<p>Multiple security vulnerabilities affect the renovate package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ce10526"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-275993</id>
    <title>EUVD-2026-275993</title>
    <updated>2026-10-03T11:12:14.910545+00:00</updated>
    <content>EUVD-2026-275993</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-275993"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-2581</id>
    <title>fkie_cve-2026-2581</title>
    <updated>2026-10-03T11:12:14.910558+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>This is an uncontrolled resource consumption vulnerability (CWE-400) that can lead to Denial of Service (DoS).</p>
<p>In vulnerable Undici versions, when interceptors.deduplicate() is enabled, response data for deduplicated requests could be accumulated in memory for downstream handlers. An attacker-controlled or untrusted upstream endpoint can exploit this with large/chunked responses and concurrent identical requests, causing high memory usage and potential OOM process termination.</p>
<p>Impacted users are applications that use Undici’s deduplication interceptor against endpoints that may produce large or long-lived response bodies.</p>
<p>PatchesThe issue has been patched by changing deduplication behavior to stream response chunks to downstream handlers as they arrive (instead of full-body accumulation), and by preventing late deduplication when body streaming has already started.</p>
<p>Users should upgrade to the first official Undici (and Node.js, where applicable) releases that include this patch.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-2581"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-phc3-fgpg-7m6h</id>
    <title>GHSA-phc3-fgpg-7m6h — Undici has Unbounded Memory Consumption in its DeduplicationHandler via Response Buffering that leads to DoS</title>
    <updated>2026-10-03T11:12:14.910592+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: undici</p>
<p>## Impact
This is an uncontrolled resource consumption vulnerability (CWE-400) that can lead to Denial of Service (DoS).</p>
<p>In vulnerable Undici versions, when `interceptors.deduplicate()` is enabled, response data for deduplicated requests could be accumulated in memory for downstream handlers. An attacker-controlled or untrusted upstream endpoint can exploit this with large/chunked responses and concurrent identical requests, causing high memory usage and potential OOM process termination.</p>
<p>Impacted users are applications that use Undici’s deduplication interceptor against endpoints that may produce large or long-lived response bodies.</p>
<p>## Patches</p>
<p>The issue has been patched by changing deduplication behavior to stream response chunks to downstream handlers as they arrive (instead of full-body accumulation), and by preventing late deduplication when body streaming has already started.</p>
<p>Users should upgrade to the first official Undici (and Node.js, where applicable) releases that include this patch.</p>
<p>## Workarounds
If upgrading immediately is not possible:</p>
<p>- Disable `interceptors.deduplicate()` for affected clients/routes.
- Use `skipHeaderNames` with a marker header to force high-risk requests to bypass deduplication.
- Avoid concurrent identical requests to untrusted endpoints that may return very large/chunked bodies.
- Apply upstream/proxy response-size and timeout limits.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-phc3-fgpg-7m6h"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11121-1</id>
    <title>openSUSE-SU-2026:11121-1 — corepack24-24.17.0-1.1 on GA media</title>
    <updated>2026-10-03T11:12:14.910627+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>corepack24-24.17.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11121-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22565-1</id>
    <title>SUSE-SU-2026:22565-1 — Security update for nodejs24</title>
    <updated>2026-10-03T11:12:14.910656+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for nodejs24</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22565-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-2581</id>
    <title>UBUNTU-CVE-2026-2581</title>
    <updated>2026-10-03T11:12:14.910684+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:24.04:LTS: node-undici, Ubuntu:25.10: node-undici, Ubuntu:26.04:LTS: node-undici</p>
<p>This is an uncontrolled resource consumption vulnerability (CWE-400) that can lead to Denial of Service (DoS). In vulnerable Undici versions, when interceptors.deduplicate() is enabled, response data for deduplicated requests could be accumulated in memory for downstream handlers. An attacker-controlled or untrusted upstream endpoint can exploit this with large/chunked responses and concurrent identical requests, causing high memory usage and potential OOM process termination. Impacted users are applications that use Undici’s deduplication interceptor against endpoints that may produce large or long-lived response bodies. PatchesThe issue has been patched by changing deduplication behavior to stream response chunks to downstream handlers as they arrive (instead of full-body accumulation), and by preventing late deduplication when body streaming has already started. Users should upgrade to the first official Undici (and Node.js, where applicable) releases that include this patch.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-2581"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0933</id>
    <title>WID-SEC-W-2026-0933 — IBM App Connect Enterprise (Hono und Undici): Mehrere Schwachstellen</title>
    <updated>2026-10-03T11:12:14.910714+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen oder andere nicht näher bezeichnete Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0933"/>
  </entry>
</feed>
