<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T08:44:07.803984+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</id>
    <title>certfr-2026-avi-1094 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-04T08:44:08.366380+00:00</updated>
    <content>certfr-2026-avi-1094</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-dy27694</id>
    <title>CLEANSTART-2026-DY27694 — Security fix for CVE-2026-44240 applied in: proxy-agent 6.5.0-r0, proxy-agent 7.0.0-r2, proxy-agent 8.0.2-r0</title>
    <updated>2026-10-04T08:44:08.366461+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: proxy-agent</p>
<p>CVE-2026-44240 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-dy27694"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-318447</id>
    <title>EUVD-2026-318447</title>
    <updated>2026-10-04T08:44:08.366499+00:00</updated>
    <content>EUVD-2026-318447</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-318447"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44240</id>
    <title>fkie_cve-2026-44240</title>
    <updated>2026-10-04T08:44:08.366513+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>basic-ftp is an FTP client for Node.js. Prior to 5.3.1, basic-ftp is vulnerable to client-side denial of service when parsing FTP control-channel multiline responses. A malicious or compromised FTP server can send an unterminated multiline response during the initial FTP banner phase, before authentication. The client keeps appending attacker-controlled data into FtpContext._partialResponse and repeatedly reparses the accumulated buffer without enforcing a maximum control response size. As a result, an application using basic-ftp can remain stuck in connect() while memory and CPU usage grow under attacker-controlled input. This can lead to process-level denial of service, container OOM kills, worker restarts, queue backlog, or service degradation in applications that automatically connect to FTP endpoints. This vulnerability is fixed in 5.3.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-44240"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rpmf-866q-6p89</id>
    <title>GHSA-rpmf-866q-6p89 — basic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response…</title>
    <updated>2026-10-04T08:44:08.366540+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: basic-ftp</p>
<p>## Summary</p>
<p>`basic-ftp` is vulnerable to client-side denial of service when parsing FTP control-channel multiline responses.</p>
<p>A malicious or compromised FTP server can send an unterminated multiline response during the initial FTP banner phase, before authentication. The client keeps appending attacker-controlled data into `FtpContext._partialResponse` and repeatedly reparses the accumulated buffer without enforcing a maximum control response size.</p>
<p>As a result, an application using `basic-ftp` can remain stuck in `connect()` while memory and CPU usage grow under attacker-controlled input. This can lead to process-level denial of service, container OOM kills, worker restarts, queue backlog, or service degradation in applications that automatically connect to FTP endpoints.</p>
<p>---</p>
<p>## Details</p>
<p>### Root cause</p>
<p>The root cause is that incomplete FTP multiline control responses are buffered without an upper bound.</p>
<p>`FtpContext` stores incomplete control-channel data in `_partialResponse`:</p>
<p>https://github.com/patrickjuchli/basic-ftp/blob/50827c73ca6c1d786c97276e47be8a33d0f2277d/src/FtpContext.ts#L63-L64</p>
<p>Incoming control-channel data is handled in `_onControlSocketData`. The implementation concatenates the previous incomplete response with the new chunk, parses the entire accumulated string, and stores `parsed.rest` back into `_partialResponse`:</p>
<p>https://github.com/patrickjuchli/basic-ftp/blob/50827c73ca6c1d786c97276e47be8a33d0f2277d/src/FtpContext.ts#L328-L340</p>
<p>The relevant flo…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rpmf-866q-6p89"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:48693</id>
    <title>RHSA-2026:48693 — Red Hat Security Advisory: OpenShift Container Platform 4.22.8 bug fix and security update</title>
    <updated>2026-10-04T08:44:08.366608+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>form-data: form-data: Form field override via CRLF injection hypershift: Konnectivity proxy-server accepts agent connections without validating client certificates golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters basic-ftp: basic-ftp: Client-side Denial of Service via unterminated multiline FTP responses ws: ws: Uninitialized memory disclosure via `websocket.close()` with `TypedArray` golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:48693"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-44240</id>
    <title>UBUNTU-CVE-2026-44240</title>
    <updated>2026-10-04T08:44:08.366640+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:24.04:LTS: node-proxy-agents, Ubuntu:25.10: node-proxy-agents, Ubuntu:26.04:LTS: node-proxy-agents</p>
<p>basic-ftp is an FTP client for Node.js. Prior to 5.3.1, basic-ftp is vulnerable to client-side denial of service when parsing FTP control-channel multiline responses. A malicious or compromised FTP server can send an unterminated multiline response during the initial FTP banner phase, before authentication. The client keeps appending attacker-controlled data into FtpContext._partialResponse and repeatedly reparses the accumulated buffer without enforcing a maximum control response size. As a result, an application using basic-ftp can remain stuck in connect() while memory and CPU usage grow under attacker-controlled input. This can lead to process-level denial of service, container OOM kills, worker restarts, queue backlog, or service degradation in applications that automatically connect to FTP endpoints. This vulnerability is fixed in 5.3.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-44240"/>
  </entry>
</feed>
