<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T20:33:39.792485+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0372</id>
    <title>certfr-2026-avi-0372 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T20:33:41.208273+00:00</updated>
    <content>certfr-2026-avi-0372</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0372"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-yp71485</id>
    <title>CLEANSTART-2026-YP71485 — Immutable</title>
    <updated>2026-10-02T20:33:41.208368+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: argo-workflows</p>
<p>Security vulnerability affects the argo-workflows package. Immutable.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-yp71485"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-366106</id>
    <title>EUVD-2026-366106</title>
    <updated>2026-10-02T20:33:41.208407+00:00</updated>
    <content>EUVD-2026-366106</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-366106"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-29063</id>
    <title>fkie_cve-2026-29063</title>
    <updated>2026-10-02T20:33:41.208423+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-29063"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-wf6x-7x77-mvgw</id>
    <title>GHSA-wf6x-7x77-mvgw — Immutable is vulnerable to Prototype Pollution</title>
    <updated>2026-10-02T20:33:41.208501+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: immutable</p>
<p>## Impact
_What kind of vulnerability is it? Who is impacted?_</p>
<p>A Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs.</p>
<p>## Affected APIs</p>
<p>| API                                     | Notes                                                       |
| --------------------------------------- | ----------------------------------------------------------- |
| `mergeDeep(target, source)`              | Iterates source keys via `ObjectSeq`, assigns `merged[key]` |
| `mergeDeepWith(merger, target, source)`  | Same code path                                              |
| `merge(target, source)`                    | Shallow variant, same assignment logic                      |
| `Map.toJS()`                              | `object[k] = v` in `toObject()` with no `__proto__` guard   |
| `Map.toObject()`                            | Same `toObject()` implementation                            |
| `Map.mergeDeep(source)`                  | When source is converted to plain object                    |</p>
<p>## Patches
_Has the problem been patched? What versions should users upgrade to?_</p>
<p>| major version | patched version |
| --- | --- |
| 3.x | 3.8.3 |
| 4.x | 4.3.7 |
| 5.x | 5.1.5 |</p>
<p>## Workarounds
_Is there a way for users to fix or remediate the vulnerability without upgrading?_</p>
<p>- [Validate user input](https://developer.mozilla.org/en-US/docs/Web/Security/Attacks/Prototype_pollution#validate_user_input)
- [Node.js fl…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-wf6x-7x77-mvgw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:11070</id>
    <title>RHSA-2026:11070 — Red Hat Security Advisory: RHACS 4.8.11 security and bug fix update</title>
    <updated>2026-10-02T20:33:41.208596+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution github.com/jackc/pgproto3/v2: github.com/jackc/pgproto3/v2: Denial of Service via malicious PostgreSQL server google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:11070"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-29063</id>
    <title>UBUNTU-CVE-2026-29063</title>
    <updated>2026-10-02T20:33:41.208632+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:20.04:LTS: node-immutable, Ubuntu:22.04:LTS: node-immutable, Ubuntu:24.04:LTS: node-immutable, Ubuntu:25.10: node-immutable, Ubuntu:26.04:LTS: node-immutable</p>
<p>Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-29063"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0845</id>
    <title>WID-SEC-W-2026-0845 — IBM WebSphere Application Server Liberty: Mehrere Schwachstellen</title>
    <updated>2026-10-02T20:33:41.208661+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in IBM WebSphere Application Server Liberty ausnutzen, um seine Privilegien zu erhöhen, Sicherheitsmaßnahmen zu umgehen und Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0845"/>
  </entry>
</feed>
