<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T20:12:28.097419+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0788</id>
    <title>certfr-2026-avi-0788 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T20:12:28.491964+00:00</updated>
    <content>certfr-2026-avi-0788</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0788"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-az83054</id>
    <title>CLEANSTART-2026-AZ83054 — Security fix for CVE-2026-45740 applied in: azure-functions-node 4.1052.200-r0, jitsucom-jitsu 2.14.0-r1</title>
    <updated>2026-10-03T20:12:28.492033+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: azure-functions-node, CleanStart: jitsucom-jitsu</p>
<p>CVE-2026-45740 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-az83054"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-318167</id>
    <title>EUVD-2026-318167</title>
    <updated>2026-10-03T20:12:28.492075+00:00</updated>
    <content>EUVD-2026-318167</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-318167"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45740</id>
    <title>fkie_cve-2026-45740</title>
    <updated>2026-10-03T20:12:28.492091+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.8 and 8.2.0, protobufjs could recurse without a depth limit while expanding nested JSON descriptors through Root.fromJSON() and Namespace.addJSON(). A crafted JSON descriptor with deeply nested namespace definitions could cause the JavaScript call stack to be exhausted during descriptor loading. This vulnerability is fixed in 7.5.8 and 8.2.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-45740"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jggg-4jg4-v7c6</id>
    <title>GHSA-jggg-4jg4-v7c6 — protobufjs: Denial of Service via unbounded recursive JSON descriptor expansion</title>
    <updated>2026-10-03T20:12:28.492115+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: protobufjs</p>
<p>## Summary</p>
<p>protobufjs could recurse without a depth limit while expanding nested JSON descriptors through `Root.fromJSON()` and `Namespace.addJSON()`.</p>
<p>A crafted JSON descriptor with deeply nested namespace definitions could cause the JavaScript call stack to be exhausted during descriptor loading.</p>
<p>## Impact</p>
<p>An attacker who can provide JSON descriptors loaded by an application may be able to crash the process or otherwise cause schema loading to fail with a stack overflow.</p>
<p>This affects applications that load JSON descriptors from untrusted sources with affected versions.</p>
<p>## Preconditions</p>
<p>- The application must load JSON descriptor data influenced by an attacker.
- The crafted descriptor must contain deeply nested `nested` namespace objects.
- The affected `Root.fromJSON()` / `Namespace.addJSON()` descriptor expansion path must process the crafted input.</p>
<p>## Workarounds</p>
<p>Avoid loading untrusted protobuf JSON descriptors with affected versions. If immediate upgrade is not possible, reject excessively nested descriptor structures at an outer validation boundary where feasible, or isolate descriptor loading in a process that can be safely restarted.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jggg-4jg4-v7c6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:41929</id>
    <title>RHSA-2026:41929 — Red Hat Security Advisory: Red Hat Developer Hub 1.9.7 release.</title>
    <updated>2026-10-03T20:12:28.492149+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy form-data: form-data: Form field override via CRLF injection undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header opentelemetry-js: opentelemetry/exporter-prometheus: opentelemetry-js: Denial of Service via malformed HTTP request protobufjs: protobufjs: Denial of Service via crafted JSON descriptors</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:41929"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2452</id>
    <title>WID-SEC-W-2026-2452 — Red Hat Ansible Automation Platform (node-tar, linkify-it, protobufjs, brace-expansion, fast-uri, DOMPurify): Mehrere S…</title>
    <updated>2026-10-03T20:12:28.492185+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu manipulieren, einen Denial-of-Service-Zustand auszulösen oder beliebigen Code auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2452"/>
  </entry>
</feed>
