<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T13:05:23.216278+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-09331</id>
    <title>bdu:2026-09331</title>
    <updated>2026-10-02T13:05:23.928401+00:00</updated>
    <content>bdu:2026-09331</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-09331"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0773</id>
    <title>certfr-2026-avi-0773 — De multiples vulnérabilités ont été découvertes dans les produits Atlassian. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-02T13:05:23.928478+00:00</updated>
    <content>certfr-2026-avi-0773</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0773"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-of42288</id>
    <title>CLEANSTART-2026-OF42288 — Security fix for CVE-2026-45736 applied in: argo-workflows 3.6.19-r8, argo-workflows 3.7.15-r3</title>
    <updated>2026-10-02T13:05:23.928500+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: argo-workflows</p>
<p>CVE-2026-45736 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-of42288"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-366764</id>
    <title>EUVD-2026-366764</title>
    <updated>2026-10-02T13:05:23.928542+00:00</updated>
    <content>EUVD-2026-366764</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-366764"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45736</id>
    <title>fkie_cve-2026-45736</title>
    <updated>2026-10-02T13:05:23.928555+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-45736"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-58qx-3vcg-4xpx</id>
    <title>GHSA-58qx-3vcg-4xpx — ws: Uninitialized memory disclosure</title>
    <updated>2026-10-02T13:05:23.928578+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: ws</p>
<p>### Impact</p>
<p>The `websocket.close()` implementation is vulnerable to uninitialized memory disclosure when a `TypedArray` is passed as the reason argument.</p>
<p>### Proof of concept</p>
<p>```js
import { deepStrictEqual } from 'node:assert';
import { WebSocket, WebSocketServer } from 'ws';</p>
<p>const wss = new WebSocketServer(
  { port: 0, skipUTF8Validation: true },
  function () {
    const { port } = wss.address();
    const ws = new WebSocket(`ws://localhost:${port}`, {
      skipUTF8Validation: true
    });</p>
<p>ws.on('close', function (code, reason) {
      deepStrictEqual(reason, Buffer.alloc(80));
    });
  }
);</p>
<p>wss.on('connection', function (ws) {
  ws.close(1000, new Float32Array(20));
});
```</p>
<p>### Patches</p>
<p>The vulnerability was fixed in ws@8.20.1 (https://github.com/websockets/ws/commit/c0327ec15a54d701eb6ccefaa8bef328cfc03086).</p>
<p>### Credits</p>
<p>Credit for the private and responsible disclosure of this issue goes to [Nikita Skovoroda](https://github.com/ChALkeR).</p>
<p>### Remarks</p>
<p>Although the calculated CVSS severity is medium, the actual severity is believed to be low, as the flaw is only exploitable through misuse that is unlikely in practice.</p>
<p>### Resources</p>
<p>- https://github.com/advisories/GHSA-58qx-3vcg-4xpx
- https://www.cve.org/CVERecord?id=CVE-2026-45736</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-58qx-3vcg-4xpx"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-45736</id>
    <title>msrc_CVE-2026-45736 — ws: Uninitialized memory disclosure</title>
    <updated>2026-10-02T13:05:23.928617+00:00</updated>
    <content>msrc_CVE-2026-45736</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-45736"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11705-1</id>
    <title>openSUSE-SU-2026:11705-1 — kimi-code-0.41.0-1.1 on GA media</title>
    <updated>2026-10-02T13:05:23.928635+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kimi-code-0.41.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11705-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:26638</id>
    <title>RHSA-2026:26638 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-02T13:05:23.928651+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>dotnet: .NET: Local file tampering via link following vulnerability dotnet: ASP.NET Core: Denial of Service via uncontrolled resource consumption ws: ws: Uninitialized memory disclosure via `websocket.close()` with `TypedArray` ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass dotnet: .NET Framework: Denial of Service via improper input validation dotnet: .NET: Denial of Service due to uncontrolled resource allocation dotnet: .NET: Local tampering via improper link resolution dotnet: .NET Framework: Denial of Service via network-based buffer overflow dotnet: .NET: Security feature bypass due to incorrect authorization dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM .NET: .NET: Network Spoofing Vulnerability ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation dotnet: .NET Core: Denial of Service via type confusion</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:26638"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-45736</id>
    <title>UBUNTU-CVE-2026-45736</title>
    <updated>2026-10-02T13:05:23.928691+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: node-ws, Ubuntu:18.04:LTS: node-ws, Ubuntu:20.04:LTS: node-ws, Ubuntu:22.04:LTS: node-ws, Ubuntu:24.04:LTS: node-ws, Ubuntu:25.10: node-ws, Ubuntu:26.04:LTS: node-ws</p>
<p>ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-45736"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1955</id>
    <title>WID-SEC-W-2026-1955 — Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management: Mehrere Schwachstellen</title>
    <updated>2026-10-02T13:05:23.928722+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1955"/>
  </entry>
</feed>
