<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:21:15.463982+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-09109</id>
    <title>bdu:2026-09109</title>
    <updated>2026-10-02T14:21:15.851405+00:00</updated>
    <content>bdu:2026-09109</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-09109"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0788</id>
    <title>certfr-2026-avi-0788 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T14:21:15.851476+00:00</updated>
    <content>certfr-2026-avi-0788</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0788"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-rz36238</id>
    <title>Withdrawn: CLEANSTART-2026-RZ36238 — Security fixes in azure-functions-node 4.1052.200-r0</title>
    <updated>2026-10-02T14:21:15.851501+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: azure-functions-node</p>
<p>Package azure-functions-node version 4.1052.200-r0 fixes 22 vulnerabilities: CVE-2026-41907, CVE-2026-48068, CVE-2026-48069, CVE-2024-37168, CVE-2024-4068...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-rz36238"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-365497</id>
    <title>EUVD-2026-365497</title>
    <updated>2026-10-02T14:21:15.851534+00:00</updated>
    <content>EUVD-2026-365497</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-365497"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44293</id>
    <title>fkie_cve-2026-44293</title>
    <updated>2026-10-02T14:21:15.851547+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated JavaScript for toObject conversion could include an unsafe expression derived from a schema-controlled bytes field default value. A crafted descriptor with a non-string default value for a bytes field could cause attacker-controlled code to be emitted into the generated conversion function. This vulnerability is fixed in 7.5.6 and 8.0.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-44293"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-66ff-xgx4-vchm</id>
    <title>GHSA-66ff-xgx4-vchm — protobuf.js: Code injection through bytes field defaults in generated toObject code</title>
    <updated>2026-10-02T14:21:15.851570+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: protobufjs</p>
<p>## Summary</p>
<p>protobufjs generated JavaScript for `toObject` conversion could include an unsafe expression derived from a schema-controlled `bytes` field default value. A crafted descriptor with a non-string default value for a `bytes` field could cause attacker-controlled code to be emitted into the generated conversion function.</p>
<p>## Impact</p>
<p>An attacker who can provide or influence a protobuf descriptor may be able to execute arbitrary JavaScript in the context of the process using protobufjs.</p>
<p>This requires the application to load an attacker-controlled schema or descriptor and then convert a message of the affected type with defaults enabled. Applications that only use trusted, application-defined schemas are not directly affected by this issue.</p>
<p>## Preconditions</p>
<p>- The application must allow an attacker to control or influence a protobuf JSON descriptor or equivalent reflected schema.
- The descriptor must define a `bytes` field with an attacker-controlled default value.
- The application must call `toObject` with defaults enabled for the affected type.</p>
<p>## Workarounds</p>
<p>Do not load protobuf schemas or JSON descriptors from untrusted sources with affected versions. If untrusted schemas must be accepted, validate or restrict field options before loading them and run schema processing in an isolated environment.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-66ff-xgx4-vchm"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:26090</id>
    <title>RHSA-2026:26090 — Red Hat Security Advisory: Kiali 2.22.5 for Red Hat OpenShift Service Mesh 3.3</title>
    <updated>2026-10-02T14:21:15.851605+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation protobufjs: protobufjs: Arbitrary code execution due to unsafe expression generation from crafted protobuf descriptors</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:26090"/>
  </entry>
</feed>
