<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T19:32:57.077137+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0698</id>
    <title>certfr-2026-avi-0698 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T19:32:57.729539+00:00</updated>
    <content>certfr-2026-avi-0698</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0698"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-be61221</id>
    <title>Withdrawn: CLEANSTART-2026-BE61221 — Security fixes for CVE-2025-62718, CVE-2025-69873, CVE-2026-29045, CVE-2026-29085, CVE-2026-29086, CVE-2026-29087, CVE-…</title>
    <updated>2026-10-03T19:32:57.729630+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: opensearch-dashboards-fips</p>
<p>Multiple security vulnerabilities affect the opensearch-dashboards-fips package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-be61221"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-366120</id>
    <title>EUVD-2026-366120</title>
    <updated>2026-10-03T19:32:57.729676+00:00</updated>
    <content>EUVD-2026-366120</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-366120"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42033</id>
    <title>fkie_cve-2026-42033</title>
    <updated>2026-10-03T19:32:57.729691+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has been polluted by any co-dependency with keys that axios reads without a hasOwnProperty guard, an attacker can (a) silently intercept and modify every JSON response before the application sees it, or (b) fully hijack the underlying HTTP transport, gaining access to request credentials, headers, and body. The precondition is prototype pollution from a separate source in the same process. This vulnerability is fixed in 1.15.1 and 0.31.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-42033"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-pf86-5x62-jrwf</id>
    <title>GHSA-pf86-5x62-jrwf — Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking</title>
    <updated>2026-10-03T19:32:57.729718+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: axios</p>
<p>## Summary</p>
<p>When `Object.prototype` has been polluted by any co-dependency with keys that axios reads without a `hasOwnProperty` guard, an attacker can (a) silently intercept and modify every JSON response before the application sees it, or (b) fully hijack the underlying HTTP transport, gaining access to request credentials, headers, and body. The precondition is prototype pollution from a separate source in the same process -- lodash &lt; 4.17.21, or any of several other common npm packages with known PP vectors. The two gadgets confirmed here work independently.</p>
<p>---</p>
<p>## Background: how mergeConfig builds the config object</p>
<p>Every axios request goes through `Axios._request` in [`lib/core/Axios.js#L76`](https://github.com/axios/axios/blob/v1.13.6/lib/core/Axios.js#L76):</p>
<p>```js
config = mergeConfig(this.defaults, config);
```</p>
<p>Inside `mergeConfig`, the merged config is built as a plain `{}` object ([`lib/core/mergeConfig.js#L20`](https://github.com/axios/axios/blob/v1.13.6/lib/core/mergeConfig.js#L20)):</p>
<p>```js
const config = {};
```</p>
<p>A plain `{}` inherits from `Object.prototype`. `mergeConfig` only iterates `Object.keys({ ...config1, ...config2 })` ([line 99](https://github.com/axios/axios/blob/v1.13.6/lib/core/mergeConfig.js#L99)), which is a spread of own properties. Any key that is absent from both `this.defaults` and the per-request config will never be set as an own property on the merged config. Reading that key later on the merged config falls through to `Object.prototyp…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-pf86-5x62-jrwf"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0325</id>
    <title>NCSC-2026-0325 — Kwetsbaarheden verholpen in Atlassian producten</title>
    <updated>2026-10-03T19:32:57.729835+00:00</updated>
    <content>NCSC-2026-0325</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0325"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:14937</id>
    <title>RHSA-2026:14937 — Red Hat Security Advisory: A Subscription Management tool for finding and reporting Red Hat product usage</title>
    <updated>2026-10-03T19:32:57.729963+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization libarchive: libarchive: Information disclosure via heap out-of-bounds read in RAR archive processing libcap: libcap: Privilege escalation via TOCTOU race condition in cap_set_file() libarchive: libarchive: Arbitrary code execution via integer overflow in ISO9660 image processing nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing OpenSSH: OpenSSH: Privilege escalation via scp legacy protocol when not preserving file mode OpenSSH: OpenSSH: Arbitrary command execution via shell metacharacters in username OpenSSH: OpenSSH: Information disclosure due to unintended cryptographic algorithm usage OpenSSH: OpenSSH: Low integrity impact from unconfirmed proxy-mode multiplexing sessions OpenSSH: OpenSSH: Security bypass via mishandling of authorized_keys principals option axios: Axios: Remote Code Execution via Prototype Pollution escalation follow-redirects: follow-redirects: Information disclosure via cross-domain redirects axios: Axios: HTTP Transport Hijacking via Prototype Pollution axios: Axios: Arbitrary HTTP header injection via prototype pollution axios: Node.js: Axios: Denial of Service via unbounded recursion in toFormData with deeply nested request data axios: Axios: Authentication bypass due to prototype pollution of HTTP error handling axi…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:14937"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42033</id>
    <title>UBUNTU-CVE-2026-42033</title>
    <updated>2026-10-03T19:32:57.730016+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:20.04:LTS: node-axios, Ubuntu:Pro:22.04:LTS: node-axios, Ubuntu:Pro:24.04:LTS: node-axios, Ubuntu:25.10: node-axios, Ubuntu:Pro:26.04:LTS: node-axios</p>
<p>Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has been polluted by any co-dependency with keys that axios reads without a hasOwnProperty guard, an attacker can (a) silently intercept and modify every JSON response before the application sees it, or (b) fully hijack the underlying HTTP transport, gaining access to request credentials, headers, and body. The precondition is prototype pollution from a separate source in the same process. This vulnerability is fixed in 1.15.1 and 0.31.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42033"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1450</id>
    <title>WID-SEC-W-2026-1450 — IBM App Connect Enterprise (Axios): Mehrere Schwachstellen</title>
    <updated>2026-10-03T19:32:57.730047+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen, wodurch weitere Angriffe möglich werden.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1450"/>
  </entry>
</feed>
