<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T05:25:47.569178+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-bs35481</id>
    <title>CLEANSTART-2026-BS35481 — Security fix for CVE-2026-48758 applied in: pulumi 3.248.0-r0, renovate 44.31.0-r2, renovate 44.32.4-r1, renovate 44.32…</title>
    <updated>2026-10-03T05:25:47.649483+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: pulumi, CleanStart: renovate</p>
<p>CVE-2026-48758 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-bs35481"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-337879</id>
    <title>EUVD-2026-337879</title>
    <updated>2026-10-03T05:25:47.649541+00:00</updated>
    <content>EUVD-2026-337879</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-337879"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48758</id>
    <title>fkie_cve-2026-48758</title>
    <updated>2026-10-03T05:25:47.649557+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 3.2.1, the preAuthEncoding function in @sigstore/core uses Node.js ascii encoding when converting the PAE string to bytes, allowing payloadType to be mutated after signing without invalidating the signature and breaking the type-binding guarantee that DSSE is designed to provide. This issue is fixed in version 3.2.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-48758"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jfc7-64v2-mr8c</id>
    <title>GHSA-jfc7-64v2-mr8c — @sigstore/core has DSSE payloadType type-binding failure</title>
    <updated>2026-10-03T05:25:47.649581+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @sigstore/core</p>
<p>### Impact
The `preAuthEncoding` function in `@sigstore/core` uses Node.js `'ascii'` encoding when converting the PAE (Pre-Authentication Encoding) string to bytes. This allows `payloadType` to be mutated after signing without invalidating the signature, breaking the type-binding guarantee that DSSE is designed to provide.</p>
<p>In `packages/core/src/dsse.ts`, the PAE function builds a string containing `payloadType` and then encodes it with `Buffer.from(prefix, 'ascii')`.</p>
<p>In Node.js, `'ascii'` encoding for string-to-Buffer is equivalent to `'latin1'`, which **truncates characters above U+00FF to their low byte**. This means for any ASCII character, there exist Unicode characters (at U+01xx, U+02xx, etc.) that produce the identical encoded byte:</p>
<p>| Original | Codepoint | Mutant | Codepoint | Encoded byte |
|----------|-----------|--------|-----------|--------------|
| `t`      | U+0074    | `Ŵ`    | U+0174    | `0x74`       |
| `e`      | U+0065    | `ť`    | U+0165    | `0x65`       |</p>
<p>An attacker can substitute every character in `payloadType` with a Unicode variant whose low byte matches, producing **identical PAE bytes** and a passing signature verification.</p>
<p>Additionally, `payloadType.length` returns the JavaScript string length (UTF-16 code units) rather than the UTF-8 byte length required by the DSSE spec, though this is only a contributing factor for non-ASCII types.</p>
<p>#### Reproduction</p>
<p>```javascript
const { preAuthEncoding } = require('@sigstore/core/dist/dsse.js');
con…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jfc7-64v2-mr8c"/>
  </entry>
</feed>
