<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T23:37:55.004177+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-sj56797</id>
    <title>CLEANSTART-2026-SJ56797 — Security fix for CVE-2026-32887 applied in: jitsucom-jitsu 2.11.0-r3</title>
    <updated>2026-10-03T23:37:55.077865+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: jitsucom-jitsu</p>
<p>Security vulnerability affects the jitsucom-jitsu package. This issue is resolved in later releases. See references for vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-sj56797"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-277346</id>
    <title>EUVD-2026-277346</title>
    <updated>2026-10-03T23:37:55.077928+00:00</updated>
    <content>EUVD-2026-277346</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-277346"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32887</id>
    <title>fkie_cve-2026-32887</title>
    <updated>2026-10-03T23:37:55.077945+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Effect is a TypeScript framework that consists of several packages that work together to help build TypeScript applications. Prior to version 3.20.0, when using `RpcServer.toWebHandler` (or `HttpApp.toWebHandlerRuntime`) inside a Next.js App Router route handler, any Node.js `AsyncLocalStorage`-dependent API called from within an Effect fiber can read another concurrent request's context — or no context at all. Under production traffic, `auth()` from `@clerk/nextjs/server` returns a different user's session. Version 3.20.0 contains a fix for the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-32887"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-38f7-945m-qr2g</id>
    <title>GHSA-38f7-945m-qr2g — Effect `AsyncLocalStorage` context lost/contaminated inside Effect fibers under concurrent load with RPC</title>
    <updated>2026-10-03T23:37:55.077977+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: effect</p>
<p>## Versions</p>
<p>- `effect`: 3.19.15
- `@effect/rpc`: 0.72.1
- `@effect/platform`: 0.94.2
- Node.js: v22.20.0
- Vercel runtime with Fluid compute
- Next.js: 16 (App Router)
- `@clerk/nextjs`: 6.x</p>
<p>## Root cause</p>
<p>Effect's `MixedScheduler` batches fiber continuations and drains them inside a **single** microtask or timer callback. The `AsyncLocalStorage` context active during that callback belongs to whichever request first triggered the scheduler's drain cycle — **not** the request that owns the fiber being resumed.</p>
<p>### Detailed mechanism</p>
<p>#### 1. Scheduler batching (`effect/src/Scheduler.ts`, `MixedScheduler`)</p>
<p>```typescript
// MixedScheduler.starve() — called once when first task is scheduled
private starve(depth = 0) {
  if (depth &gt;= this.maxNextTickBeforeTimer) {
    setTimeout(() =&gt; this.starveInternal(0), 0)       // timer queue
  } else {
    Promise.resolve(void 0).then(() =&gt; this.starveInternal(depth + 1)) // microtask queue
  }
}</p>
<p>// MixedScheduler.starveInternal() — drains ALL accumulated tasks in one call
private starveInternal(depth: number) {
  const tasks = this.tasks.buckets
  this.tasks.buckets = []
  for (const [_, toRun] of tasks) {
    for (let i = 0; i &lt; toRun.length; i++) {
      toRun[i]()  // ← Every fiber continuation runs in the SAME ALS context
    }
  }
  // ...
}
```</p>
<p>`scheduleTask` only calls `starve()` when `running` is `false`. Subsequent tasks accumulate in `this.tasks` until `starveInternal` drains them all. The `Promise.then()` (or `setTimeout`…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-38f7-945m-qr2g"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3046</id>
    <title>WID-SEC-W-2026-3046 — IBM Concert: Mehrere Schwachstellen</title>
    <updated>2026-10-03T23:37:55.078073+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM Concert ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, um einen SQL-Injection Angriff durchzuführen und um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3046"/>
  </entry>
</feed>
