<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T15:53:49.399523+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0773</id>
    <title>certfr-2026-avi-0773 — De multiples vulnérabilités ont été découvertes dans les produits Atlassian. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-02T15:53:49.632262+00:00</updated>
    <content>certfr-2026-avi-0773</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0773"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-324318</id>
    <title>EUVD-2026-324318</title>
    <updated>2026-10-02T15:53:49.632328+00:00</updated>
    <content>EUVD-2026-324318</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-324318"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42342</id>
    <title>fkie_cve-2026-42342</title>
    <updated>2026-10-02T15:53:49.632345+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>React Router is a router for React. In versions 7.0.0 through 7.14.x of react-router and versions 2.10.0 through 2.17.4 of @remix-run/server-runtime, certain crafted requests can consume disproportionate server resources via unbounded path expansion in the __manifest endpoint, resulting in response time degradation and/or service unavailability for end users. This affects React Router Framework Mode applications as well as Remix applications. This does not impact applications using Declarative Mode (`&lt;BrowserRouter&gt;`) or Data Mode (`createBrowserRouter/&lt;RouterProvider&gt;`). This is patched in react-router version 7.15.0 and @remix-run/server-runtime version 2.17.5.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-42342"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8x6r-g9mw-2r78</id>
    <title>GHSA-8x6r-g9mw-2r78 — React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint</title>
    <updated>2026-10-02T15:53:49.632380+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: react-router, npm: @remix-run/server-runtime</p>
<p>There exists a potential DOS attack vector in React Router Framework Mode applications (as well as Remix v2.10.0 - 2.17.4).  Certain requests can be crafted to consume disproportionate resources on the server, resulting in response time degredation and/or service unavailability for end users.</p>
<p>&gt; [!NOTE]
&gt; This does not impact your React Router application if you are using [Declarative Mode](https://reactrouter.com/start/modes#declarative) (`&lt;BrowserRouter&gt;`) or [Data Mode](https://reactrouter.com/start/modes#data) (`createBrowserRouter`/`&lt;RouterProvider&gt;`).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8x6r-g9mw-2r78"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:41951</id>
    <title>RHSA-2026:41951 — Red Hat Security Advisory: Red Hat Data Grid 8.6.2 security update</title>
    <updated>2026-10-02T15:53:49.632411+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>fast-uri: fast-uri: URI authority bypass due to improper delimiter handling webpack-dev-server: webpack-dev-server: Information disclosure and denial of service via improper proxy configuration form-data: form-data: Form field override via CRLF injection react-router: React Router: Cross-Site Scripting vulnerability via untrusted React Server Component redirects react-router: React Router: Denial of Service via client-side Cross-Site Scripting in RSC redirect handling micrometer: micrometer-core: Micrometer: Denial of Service via specially crafted gRPC requests micrometer-core: micrometer-jetty11: micrometer-jetty12: Micrometer: Denial of Service via specially crafted HTTP requests react-router: React Router: Remote Code Execution via prototype pollution in Framework Mode axios: Axios: Prototype pollution allows information disclosure and request manipulation react-router: @remix-run/server-runtime: React Router / Remix: Denial of Service via unbounded path expansion in __manifest endpoint netty: io.netty/netty-codec-compression: io.netty/netty-codec: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoder netty-codec-redis: Netty: Command injection via CRLF characters in Redis codec encoder netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression netty: io.netty/netty-codec-mqtt: Netty: Denial of Service due to excessive resource consumption from crafted MQTT 5 he…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:41951"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1955</id>
    <title>WID-SEC-W-2026-1955 — Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management: Mehrere Schwachstellen</title>
    <updated>2026-10-02T15:53:49.632496+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1955"/>
  </entry>
</feed>
