<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T06:13:22.421193+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-07719</id>
    <title>bdu:2026-07719</title>
    <updated>2026-10-03T06:13:22.930227+00:00</updated>
    <content>bdu:2026-07719</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-07719"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0934</id>
    <title>certfr-2026-avi-0934 — De multiples vulnérabilités ont été découvertes dans les produits Atlassian. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-03T06:13:22.930282+00:00</updated>
    <content>certfr-2026-avi-0934</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0934"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-326958</id>
    <title>EUVD-2026-326958</title>
    <updated>2026-10-03T06:13:22.930313+00:00</updated>
    <content>EUVD-2026-326958</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-326958"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44705</id>
    <title>fkie_cve-2026-44705</title>
    <updated>2026-10-03T06:13:22.930326+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>tmp is a temporary file and directory creator for node.js. Prior to 0.2.6, the tmp npm package contains a path traversal vulnerability that allows escaping the intended temporary directory when untrusted data flows into the prefix, postfix, or dir options. By embedding traversal sequences (e.g., ../) or path separators in these parameters, attackers can cause files to be created outside the configured temporary base directory at attacker-controlled locations with the privileges of the running process. This vulnerability affects applications that pass user-controlled data to tmp's file/directory creation functions without proper input sanitization. This vulnerability is fixed in 0.2.6.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-44705"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-ph9p-34f9-6g65</id>
    <title>GHSA-ph9p-34f9-6g65 — tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape</title>
    <updated>2026-10-03T06:13:22.930361+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: tmp</p>
<p>### Summary</p>
<p>The tmp npm package contains a path traversal vulnerability that allows escaping the intended temporary directory when untrusted data flows into the `prefix`, `postfix`, or `dir` options. By embedding traversal sequences (e.g., `../`) or path separators in these parameters, attackers can cause files to be created outside the configured temporary base directory at attacker-controlled locations with the privileges of the running process. This vulnerability affects applications that pass user-controlled data to tmp's file/directory creation functions without proper input sanitization.</p>
<p>### Details</p>
<p>**Root Cause:**
The vulnerability exists in tmp's path construction logic where user-supplied options are directly concatenated into file paths without sanitization or validation.</p>
<p>**Technical Flow:**
1. **Filename Construction:** tmp builds filenames as `&lt;prefix&gt;-&lt;pid&gt;-&lt;random&gt;-&lt;postfix&gt;`
2. **Path Composition:** Final path computed as `path.join(tmpDir, opts.dir, name)`
3. **Path Normalization:** Node.js `path.join()` normalizes traversal sequences, allowing escape
4. **File Creation:** File created at the resulting (potentially escaped) path</p>
<p>**Vulnerable Pattern:**
```javascript
// In tmp package internals
const name = `${opts.prefix || ''}-${process.pid}-${randomString}-${opts.postfix || ''}`;
const finalPath = path.join(tmpDir, opts.dir || '', name);
// No validation that finalPath remains within tmpDir
```</p>
<p>**Path Traversal Mechanics:**
- **prefix/postfix traversa…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-ph9p-34f9-6g65"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-44705</id>
    <title>msrc_CVE-2026-44705 — tmp: Path Traversal via unsanitized prefix/postfix enables directory escape</title>
    <updated>2026-10-03T06:13:22.930473+00:00</updated>
    <content>msrc_CVE-2026-44705</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-44705"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:56338</id>
    <title>RHSA-2026:56338 — Red Hat Security Advisory: Ansible plug-ins for Red Hat Developer Hub Product Release Update</title>
    <updated>2026-10-03T06:13:22.930492+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>webpack-dev-server: webpack-dev-server: Information disclosure and denial of service via improper proxy configuration form-data: form-data: Form field override via CRLF injection brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function tmp: path Traversal via unsanitized prefix/postfix enables directory escape postcss: PostCSS: Information disclosure and denial of service via crafted CSS input js-cookie: JavaScript Cookie: Cookie attribute manipulation via prototype pollution ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation postcss: PostCSS: Information disclosure via crafted sourceMappingURL ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass nanoid: nanoid: Predictable ID generation due to integer overflow browserslist: Browserslist: Prototype pollution leading to denial of service browserslist: Browserslist: Denial of Service via unbounded memory growth from distinct query results</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:56338"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-44705</id>
    <title>UBUNTU-CVE-2026-44705</title>
    <updated>2026-10-03T06:13:22.930531+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: node-tmp, Ubuntu:18.04:LTS: node-tmp, Ubuntu:20.04:LTS: node-tmp, Ubuntu:22.04:LTS: node-tmp, Ubuntu:24.04:LTS: node-tmp, Ubuntu:25.10: node-tmp, Ubuntu:26.04:LTS: node-tmp</p>
<p>tmp is a temporary file and directory creator for node.js. Prior to 0.2.6, the tmp npm package contains a path traversal vulnerability that allows escaping the intended temporary directory when untrusted data flows into the prefix, postfix, or dir options. By embedding traversal sequences (e.g., ../) or path separators in these parameters, attackers can cause files to be created outside the configured temporary base directory at attacker-controlled locations with the privileges of the running process. This vulnerability affects applications that pass user-controlled data to tmp's file/directory creation functions without proper input sanitization. This vulnerability is fixed in 0.2.6.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-44705"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2460</id>
    <title>WID-SEC-W-2026-2460 — Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management: Mehrere Schwachstellen</title>
    <updated>2026-10-03T06:13:22.930565+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2460"/>
  </entry>
</feed>
