<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T15:37:03.983417+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-07268</id>
    <title>bdu:2026-07268</title>
    <updated>2026-10-03T15:37:04.032206+00:00</updated>
    <content>bdu:2026-07268</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-07268"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0316</id>
    <title>certfr-2026-avi-0316 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-03T15:37:04.032248+00:00</updated>
    <content>certfr-2026-avi-0316</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0316"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ce10526</id>
    <title>Withdrawn: CLEANSTART-2026-CE10526 — Security fixes for CVE-2025-64756, CVE-2025-69873, CVE-2026-1525, CVE-2026-1526, CVE-2026-1527, CVE-2026-1528, CVE-2026…</title>
    <updated>2026-10-03T15:37:04.032267+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: renovate</p>
<p>Multiple security vulnerabilities affect the renovate package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ce10526"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-273548</id>
    <title>EUVD-2026-273548</title>
    <updated>2026-10-03T15:37:04.032305+00:00</updated>
    <content>EUVD-2026-273548</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-273548"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-27903</id>
    <title>fkie_cve-2026-27903</title>
    <updated>2026-10-03T15:37:04.032316+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.3, `matchOne()` performs unbounded recursive backtracking when a glob pattern contains multiple non-adjacent `**` (GLOBSTAR) segments and the input path does not match. The time complexity is O(C(n, k)) -- binomial -- where `n` is the number of path segments and `k` is the number of globstars. With k=11 and n=30, a call to the default `minimatch()` API stalls for roughly 5 seconds. With k=13, it exceeds 15 seconds. No memoization or call budget exists to bound this behavior. Any application where an attacker can influence the glob pattern passed to `minimatch()` is vulnerable. The realistic attack surface includes build tools and task runners that accept user-supplied glob arguments (ESLint, Webpack, Rollup config), multi-tenant systems where one tenant configures glob-based rules that run in a shared process, admin or developer interfaces that accept ignore-rule or filter configuration as globs, and CI/CD pipelines that evaluate user-submitted config files containing glob patterns. An attacker who can place a crafted pattern into any of these paths can stall the Node.js event loop for tens of seconds per invocation. The pattern is 56 bytes for a 5-second stall and does not require authentication in contexts where pattern input is part of the feature. Versions 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-27903"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7r86-cg39-jmmj</id>
    <title>GHSA-7r86-cg39-jmmj — minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments</title>
    <updated>2026-10-03T15:37:04.032348+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: minimatch</p>
<p>### Summary</p>
<p>`matchOne()` performs unbounded recursive backtracking when a glob pattern contains multiple non-adjacent `**` (GLOBSTAR) segments and the input path does not match. The time complexity is O(C(n, k)) -- binomial -- where `n` is the number of path segments and `k` is the number of globstars. With k=11 and n=30, a call to the default `minimatch()` API stalls for roughly 5 seconds. With k=13, it exceeds 15 seconds. No memoization or call budget exists to bound this behavior.</p>
<p>---</p>
<p>### Details</p>
<p>The vulnerable loop is in `matchOne()` at [`src/index.ts#L960`](https://github.com/isaacs/minimatch/blob/v10.2.2/src/index.ts#L960):</p>
<p>```typescript
while (fr &lt; fl) {
  ..
  if (this.matchOne(file.slice(fr), pattern.slice(pr), partial)) {
    ..
    return true
  }
  ..
  fr++
}
```</p>
<p>When a GLOBSTAR is encountered, the function tries to match the remaining pattern against every suffix of the remaining file segments. Each `**` multiplies the number of recursive calls by the number of remaining segments. With k non-adjacent globstars and n file segments, the total number of calls is C(n, k).</p>
<p>There is no depth counter, visited-state cache, or budget limit applied to this recursion. The call tree is fully explored before returning `false` on a non-matching input.</p>
<p>Measured timing with n=30 path segments:</p>
<p>| k (globstars) | Pattern size | Time     |
|---------------|--------------|----------|
| 7             | 36 bytes     | ~154ms   |
| 9             | 46 bytes     | ~1.2s    |
|…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7r86-cg39-jmmj"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-27903</id>
    <title>msrc_CVE-2026-27903 — minimatch has a ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments</title>
    <updated>2026-10-03T15:37:04.032404+00:00</updated>
    <content>msrc_CVE-2026-27903</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-27903"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:37387</id>
    <title>RHSA-2026:37387 — Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.22.0 security, enhancement &amp; bug fix update</title>
    <updated>2026-10-03T15:37:04.032421+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>github.com/containerd/containerd: containerd local privilege escalation containerd: containerd has an integer overflow in User ID handling runc: runc can be tricked into creating empty files/directories on host noobaa-core: Excessive permissions of /etc could lead to escalation of privilege in the noobaa-core container go-git: argument injection via the URL field go-git: go-git clients vulnerable to DoS via maliciously crafted Git server replies golang.org/x/net/proxy: golang.org/x/net/http/httpproxy: HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net golang.org/x/net/html: Quadratic parsing complexity in golang.org/x/net/html runc: opencontainers/selinux: container escape and denial of service due to arbitrary write gadgets and procfs write redirects github.com/moby/moby: Moby's Firewalld reload removes bridge network isolation github.com/ulikunitz/xz: github.com/ulikunitz/xz leaks memory github.com/containerd/containerd: containerd: Memory exhaustion via CRI Attach implementation goroutine leaks github.com/sigstore/fulcio: Fulcio: Denial of Service via crafted OpenID Connect (OIDC) token fulcio: Fulcio: Server-Side Request Forgery (SSRF) via unanchored regex in MetaIssuer URL validation github.com/sigstore/rekor: Rekor denial of service github.com/sigstore/rekor: Rekor Server-Side Request Forgery (SSRF) golang.org/x/net/html: golang.org/x/net/html: Denial of Service due to excessive HTML parsing golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:37387"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-27903</id>
    <title>UBUNTU-CVE-2026-27903</title>
    <updated>2026-10-03T15:37:04.032508+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: node-minimatch, Ubuntu:Pro:16.04:LTS: node-minimatch, Ubuntu:18.04:LTS: node-minimatch, Ubuntu:20.04:LTS: node-minimatch, Ubuntu:22.04:LTS: node-minimatch, Ubuntu:24.04:LTS: node-minimatch, Ubuntu:25.10: node-minimatch, Ubuntu:26.04:LTS: node-minimatch</p>
<p>minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.3, `matchOne()` performs unbounded recursive backtracking when a glob pattern contains multiple non-adjacent `**` (GLOBSTAR) segments and the input path does not match. The time complexity is O(C(n, k)) -- binomial -- where `n` is the number of path segments and `k` is the number of globstars. With k=11 and n=30, a call to the default `minimatch()` API stalls for roughly 5 seconds. With k=13, it exceeds 15 seconds. No memoization or call budget exists to bound this behavior. Any application where an attacker can influence the glob pattern passed to `minimatch()` is vulnerable. The realistic attack surface includes build tools and task runners that accept user-supplied glob arguments (ESLint, Webpack, Rollup config), multi-tenant systems where one tenant configures glob-based rules that run in a shared process, admin or developer interfaces that accept ignore-rule or filter configuration as globs, and CI/CD pipelines that evaluate user-submitted config files containing glob patterns. An attacker who can place a crafted pattern into any of these paths can stall the Node.js event loop for tens of seconds per invocation. The pattern is 56 bytes for a 5-second stall and does not require authentication in contexts where pattern input is part of the feature. Versions 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-27903"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0752</id>
    <title>WID-SEC-W-2026-0752 — IBM SPSS: Mehrere Schwachstellen</title>
    <updated>2026-10-03T15:37:04.032548+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM SPSS ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, um einen Denial of Service Angriff durchzuführen, und um Dateien zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0752"/>
  </entry>
</feed>
