<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T15:05:20.470473+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-357984</id>
    <title>EUVD-2026-357984</title>
    <updated>2026-10-03T15:05:20.534137+00:00</updated>
    <content>EUVD-2026-357984</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-357984"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42570</id>
    <title>fkie_cve-2026-42570</title>
    <updated>2026-10-03T15:05:20.534180+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From version 5.6.3 to before version 5.8.1, devalue.parse could, due to quirks in some JavaScript engines, be convinced to allocate much more memory than was needed when deserializing sparse arrays, leading to excessive memory consumption. This issue has been patched in version 5.8.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-42570"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-77vg-94rm-hx3p</id>
    <title>GHSA-77vg-94rm-hx3p — Svelte devalue: DoS via sparse array deserialization</title>
    <updated>2026-10-03T15:05:20.534218+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: devalue</p>
<p>`devalue.parse` could, due to quirks in some JavaScript engines, be convinced to allocate much more memory than was needed when deserializing sparse arrays, leading to excessive memory consumption.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-77vg-94rm-hx3p"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:37272</id>
    <title>RHSA-2026:37272 — Red Hat Security Advisory: RHTAS 1.4.2 - Red Hat Trusted Artifact Signer Release</title>
    <updated>2026-10-03T15:05:20.534244+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>image-size: image-size: Denial of Service due to infinite loop when processing specially crafted images. golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API devalue: devalue: Excessive memory consumption via deserialization of sparse arrays next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18n Next.js: Next.js: Authorization bypass via crafted query parameters next.js: Next.js: Unauthorized access to protected content via middleware bypass Next.js: Next.js: Denial of Service via Image Optimization API Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requests next.js: Next.js: Denial of Service via crafted POST requests to server actions next.js: Next.js: Information disclosure via security fix bypass in middleware with Turbopack ws: ws: Uninitialized memory disclosure via `websocket.close()` with `TypedArray` ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:37272"/>
  </entry>
</feed>
