<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T04:10:58.868522+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-rz36238</id>
    <title>Withdrawn: CLEANSTART-2026-RZ36238 — Security fixes in azure-functions-node 4.1052.200-r0</title>
    <updated>2026-10-04T04:10:58.923690+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: azure-functions-node</p>
<p>Package azure-functions-node version 4.1052.200-r0 fixes 22 vulnerabilities: CVE-2026-41907, CVE-2026-48068, CVE-2026-48069, CVE-2024-37168, CVE-2024-4068...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-rz36238"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-318166</id>
    <title>EUVD-2026-318166</title>
    <updated>2026-10-04T04:10:58.923749+00:00</updated>
    <content>EUVD-2026-318166</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-318166"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44295</id>
    <title>fkie_cve-2026-44295</title>
    <updated>2026-10-04T04:10:58.923765+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.2.1 and 2.0.2, pbjs static code generation could emit unsafe JavaScript identifiers derived from schema-controlled names. When generating static JavaScript from a crafted schema or JSON descriptor, certain namespace, enum, service, or derived full names could be written into the generated output without sufficient sanitization. This vulnerability is fixed in 1.2.1 and 2.0.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-44295"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6r35-46g8-jcw9</id>
    <title>GHSA-6r35-46g8-jcw9 — protobuf.js: Code injection in pbjs static output from crafted schema names</title>
    <updated>2026-10-04T04:10:58.923791+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: protobufjs-cli</p>
<p>## Summary</p>
<p>`pbjs` static code generation could emit unsafe JavaScript identifiers derived from schema-controlled names. When generating static JavaScript from a crafted schema or JSON descriptor, certain namespace, enum, service, or derived full names could be written into the generated output without sufficient sanitization.</p>
<p>## Impact</p>
<p>An attacker who can provide or influence schemas passed to `pbjs` may be able to cause generated JavaScript output to contain attacker-controlled code. The injected code would run if the generated file is later executed or imported by the application or build process.</p>
<p>This affects the protobufjs CLI static code generation path. Applications that only use trusted schemas, or that do not execute generated output from untrusted schemas, are not directly affected.</p>
<p>## Preconditions</p>
<p>- The application or build process must run `pbjs` static code generation on a schema or JSON descriptor influenced by an attacker.
- The attacker-controlled input must contain crafted schema names that reach generated JavaScript output.
- The generated JavaScript file must subsequently be executed, imported, or otherwise evaluated.</p>
<p>## Workarounds</p>
<p>Do not run affected versions of `pbjs` static code generation on untrusted schemas or descriptors. If untrusted schemas must be accepted, validate schema names before code generation and run generation in an isolated environment.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6r35-46g8-jcw9"/>
  </entry>
</feed>
