<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T01:45:00.335238+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-10885</id>
    <title>bdu:2026-10885</title>
    <updated>2026-10-03T01:45:00.497851+00:00</updated>
    <content>bdu:2026-10885</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-10885"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0788</id>
    <title>certfr-2026-avi-0788 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T01:45:00.497911+00:00</updated>
    <content>certfr-2026-avi-0788</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0788"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ag43501</id>
    <title>Withdrawn: CLEANSTART-2026-AG43501 — Security fixes in sqlpad 7.5.7-r2</title>
    <updated>2026-10-03T01:45:00.497939+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: sqlpad</p>
<p>Package sqlpad version 7.5.7-r2 fixes 26 vulnerabilities: ghsa-2v35-w6hq-6mfw, ghsa-f6ww-3ggp-fr8h, ghsa-wh4c-j3r5-mjhp, ghsa-x6wf-f3px-wcqx, ghsa-j759-j44w-7fr8...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ag43501"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-293113</id>
    <title>EUVD-2026-293113</title>
    <updated>2026-10-03T01:45:00.497972+00:00</updated>
    <content>EUVD-2026-293113</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-293113"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41907</id>
    <title>fkie_cve-2026-41907</title>
    <updated>2026-10-03T01:45:00.497986+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-41907"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-w5hq-g745-h8pq</id>
    <title>GHSA-w5hq-g745-h8pq — uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided</title>
    <updated>2026-10-03T01:45:00.498009+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: uuid</p>
<p>### Summary</p>
<p>The `v3()`, `v5()`, and `v6()` [API methods](https://github.com/uuidjs/uuid#api-summary) (not `uuid` release versions) accept external output buffers but do not reject out-of-range writes (small `buf` or large `offset`).  
By contrast, `v4()`, `v1()`, and `v7()` API methods explicitly throw `RangeError` on invalid bounds.</p>
<p>This inconsistency allows **silent partial writes** into caller-provided buffers.</p>
<p>### Affected code</p>
<p>- `src/v35.ts` (`v3()`/`v5()` path) writes `buf[offset + i]` without bounds validation.
- `src/v6.ts` writes `buf[offset + i]` without bounds validation.</p>
<p>### Reproducible PoC</p>
<p>```bash
cd /home/StrawHat/uuid
npm ci
npm run build</p>
<p>node --input-type=module -e "
import {v4,v5,v6} from './dist-node/index.js';
const ns='6ba7b810-9dad-11d1-80b4-00c04fd430c8';
for (const [name,fn] of [
  ['v4()',()=&gt;v4({},new Uint8Array(8),4)],
  ['v5()',()=&gt;v5('x',ns,new Uint8Array(8),4)],
  ['v6()',()=&gt;v6({},new Uint8Array(8),4)],
]) {
  try { fn(); console.log(name,'NO_THROW'); }
  catch(e){ console.log(name,'THREW',e.name); }
}"
```</p>
<p>Observed:</p>
<p>- `v4() THREW RangeError`
- `v5() NO_THROW`
- `v6() NO_THROW`</p>
<p>Example partial overwrite evidence captured during audit:</p>
<p>```text
same true buf [
  170, 170, 170, 170,
   75, 224, 100,  63
]
v6 [
  187, 187, 187, 187,
   31,  19, 185,  64
]
```</p>
<p>### Security impact</p>
<p>- **Primary**: integrity/robustness issue (silent partial output).
- If an application assumes full UUID writes into preallocated buffers, this can produce ma…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-w5hq-g745-h8pq"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-41907</id>
    <title>msrc_CVE-2026-41907 — uuid: Missing buffer bounds check in `v3`/`v5`/`v6` when `buf` is provided</title>
    <updated>2026-10-03T01:45:00.498059+00:00</updated>
    <content>msrc_CVE-2026-41907</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-41907"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0325</id>
    <title>NCSC-2026-0325 — Kwetsbaarheden verholpen in Atlassian producten</title>
    <updated>2026-10-03T01:45:00.498077+00:00</updated>
    <content>NCSC-2026-0325</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0325"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:56431</id>
    <title>RHSA-2026:56431 — Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.18.27 security, enhancement &amp; bug fix update</title>
    <updated>2026-10-03T01:45:00.498301+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang: net/url: Memory exhaustion in query parameter parsing in net/url crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate js-yaml: js-yaml prototype pollution in merge react-router: React Router unexpected external redirect undici: Undici: HTTP Request Smuggling and Denial of Service due to duplicate Content-Length headers undici: undici: Denial of Service via unbounded memory consumption during WebSocket permessage-deflate decompression undici: Undici: HTTP header injection and request smuggling vulnerability undici: Undici: Denial of Service via invalid WebSocket permessage-deflate extension parameter fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies fast-uri: fast-uri: URI authority bypass due to improper delimiter handling undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery. undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing postcss-selector-parser: Postcss: Denial of Service via uncontrolled recursion in AST Serialization undici: undici vulnerable to HTTP header injection via Set-Cookie percent-decoding undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header form-data: form-data: Form field override via CRLF injection undici: undici: Denial…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:56431"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-41907</id>
    <title>UBUNTU-CVE-2026-41907</title>
    <updated>2026-10-03T01:45:00.498392+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: node-uuid, Ubuntu:16.04:LTS: node-uuid, Ubuntu:18.04:LTS: node-uuid, Ubuntu:20.04:LTS: node-uuid, Ubuntu:22.04:LTS: node-uuid, Ubuntu:24.04:LTS: node-uuid, Ubuntu:25.10: node-uuid, Ubuntu:26.04:LTS: node-uuid</p>
<p>uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-41907"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2112</id>
    <title>WID-SEC-W-2026-2112 — IBM App Connect Enterprise: Mehrere Schwachstellen ermöglichen Manipulation von Daten</title>
    <updated>2026-10-03T01:45:00.498423+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Daten zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2112"/>
  </entry>
</feed>
