<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T00:32:34.041160+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-05098</id>
    <title>bdu:2026-05098</title>
    <updated>2026-10-04T00:32:34.174133+00:00</updated>
    <content>bdu:2026-05098</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-05098"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0667</id>
    <title>certfr-2026-avi-0667 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-04T00:32:34.174174+00:00</updated>
    <content>certfr-2026-avi-0667</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0667"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ka05451</id>
    <title>CLEANSTART-2026-KA05451 — Security fix for CVE-2026-39983 applied in: mongosh 2.5.10-r4, mongosh 2.6.0-r3, mongosh 2.7.0-r2, mongosh 2.8.2-r1</title>
    <updated>2026-10-04T00:32:34.174193+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: mongosh</p>
<p>CVE-2026-39983 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ka05451"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-337282</id>
    <title>EUVD-2026-337282</title>
    <updated>2026-10-04T00:32:34.174227+00:00</updated>
    <content>EUVD-2026-337282</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-337282"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-39983</id>
    <title>fkie_cve-2026-39983</title>
    <updated>2026-10-04T00:32:34.174239+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>basic-ftp is an FTP client for Node.js. Prior to 5.2.1, basic-ftp allows FTP command injection via CRLF sequences (\r\n) in file path parameters passed to high-level path APIs such as cd(), remove(), rename(), uploadFrom(), downloadTo(), list(), and removeDir(). The library's protectWhitespace() helper only handles leading spaces and returns other paths unchanged, while FtpContext.send() writes the resulting command string directly to the control socket with \r\n appended. This lets attacker-controlled path strings split one intended FTP command into multiple commands. This vulnerability is fixed in 5.2.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-39983"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-chqc-8p9q-pq6q</id>
    <title>GHSA-chqc-8p9q-pq6q — basic-ftp has FTP Command Injection via CRLF</title>
    <updated>2026-10-04T00:32:34.174267+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: basic-ftp</p>
<p>## Summary</p>
<p>`basic-ftp` version `5.2.0` allows FTP command injection via CRLF sequences (`\r\n`) in file path parameters passed to high-level path APIs such as `cd()`, `remove()`, `rename()`, `uploadFrom()`, `downloadTo()`, `list()`, and `removeDir()`. The library's `protectWhitespace()` helper only handles leading spaces and returns other paths unchanged, while `FtpContext.send()` writes the resulting command string directly to the control socket with `\r\n` appended. This lets attacker-controlled path strings split one intended FTP command into multiple commands.</p>
<p>## Affected product</p>
<p>| Product | Affected versions | Fixed version |
| --- | --- | --- |
| basic-ftp (npm) | 5.2.0 (confirmed) | no fix available as of 2026-04-04 |</p>
<p>## Vulnerability details</p>
<p>- CWE: `CWE-93` - Improper Neutralization of CRLF Sequences ('CRLF Injection')
- CVSS 3.1: `8.6` (`High`)
- Vector: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L`
- Affected component: `dist/Client.js`, all path-handling methods via `protectWhitespace()` and `send()`</p>
<p>The vulnerability exists because of two interacting code patterns:</p>
<p>**1. Inadequate path sanitization in `protectWhitespace()` (line 677):**</p>
<p>```javascript
async protectWhitespace(path) {
    if (!path.startsWith(" ")) {
        return path;  // No sanitization of \r\n characters
    }
    const pwd = await this.pwd();
    const absolutePathPrefix = pwd.endsWith("/") ? pwd : pwd + "/";
    return absolutePathPrefix + path;
}
```</p>
<p>This function only handles lead…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-chqc-8p9q-pq6q"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:13826</id>
    <title>RHSA-2026:13826 — Red Hat Security Advisory: Red Hat Developer Hub 1.9.4 release.</title>
    <updated>2026-10-04T00:32:34.174342+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization python-markdown: denial of service via malformed HTML-like sequences undici: Undici: HTTP Request Smuggling and Denial of Service due to duplicate Content-Length headers undici: undici: Denial of Service via unbounded memory consumption during WebSocket permessage-deflate decompression undici: undici: Denial of Service via crafted WebSocket frame with large length undici: Undici: Denial of Service via invalid WebSocket permessage-deflate extension parameter rhdh: GraphQL Injection Leading to Platform-Wide Denial of Service (DoS) in RH Developer Hub Orchestrator Plugin lodash: lodash: Arbitrary code execution via untrusted input in template imports path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressions Underscore.js: Underscore.js: Denial of Service via recursive data structures in flatten and isEqual functions minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution svgo: SVGO: Denial of Service via XML entity expansion backstage/plugin-techdocs-node: TechDocs Mkdocs configuration key enables arbitrary code execution flatted: flatted: Unbounded recursion DoS in parse() revive phase crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building golang: internal/syscall/unix: Root.Chmod can follow symlinks out…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:13826"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-39983</id>
    <title>UBUNTU-CVE-2026-39983</title>
    <updated>2026-10-04T00:32:34.174408+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:24.04:LTS: node-proxy-agents, Ubuntu:25.10: node-proxy-agents, Ubuntu:26.04:LTS: node-proxy-agents</p>
<p>basic-ftp is an FTP client for Node.js. Prior to 5.2.1, basic-ftp allows FTP command injection via CRLF sequences (\r\n) in file path parameters passed to high-level path APIs such as cd(), remove(), rename(), uploadFrom(), downloadTo(), list(), and removeDir(). The library's protectWhitespace() helper only handles leading spaces and returns other paths unchanged, while FtpContext.send() writes the resulting command string directly to the control socket with \r\n appended. This lets attacker-controlled path strings split one intended FTP command into multiple commands. This vulnerability is fixed in 5.2.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-39983"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1407</id>
    <title>WID-SEC-W-2026-1407 — IBM App Connect Enterprise Certified Container: Mehrere Schwachstellen</title>
    <updated>2026-10-04T00:32:34.174435+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise Certified Container ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1407"/>
  </entry>
</feed>
