<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T06:40:52.531026+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0958</id>
    <title>certfr-2026-avi-0958 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T06:40:52.586303+00:00</updated>
    <content>certfr-2026-avi-0958</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0958"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-327301</id>
    <title>EUVD-2026-327301</title>
    <updated>2026-10-03T06:40:52.586348+00:00</updated>
    <content>EUVD-2026-327301</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-327301"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-5038</id>
    <title>fkie_cve-2026-5038</title>
    <updated>2026-10-03T06:40:52.586363+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Impact: multer versions 2.0.0-alpha.1 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service when using diskStorage. Aborted or malformed multipart uploads leave orphaned partial files on disk because the Readable.pipe() call does not propagate the stream destroy signal to 
the underlying fs.WriteStream. An attacker can exhaust disk space by triggering many aborted uploads, with no application bug required.</p>
<p>Patches: Users should upgrade to multer 2.2.0 (2.x line) or 3.0.0-alpha.2 (3.x prerelease). Both versions track in-flight write streams and clean them up on the abort path.</p>
<p>Workarounds: None.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-5038"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3p4h-7m6x-2hcm</id>
    <title>GHSA-3p4h-7m6x-2hcm — Multer vulnerable to Denial of Service via incomplete cleanup of aborted uploads</title>
    <updated>2026-10-03T06:40:52.586396+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: multer</p>
<p>### Impact</p>
<p>A vulnerability in Multer allows an attacker to trigger a Denial of Service (DoS) by aborting or sending malformed multipart uploads, causing orphaned partial files to accumulate on disk when using diskStorage.</p>
<p>### Patches</p>
<p>Users should upgrade to `2.2.0`, `3.0.0-alpha.2` or higher</p>
<p>### Workarounds</p>
<p>None</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3p4h-7m6x-2hcm"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:48126</id>
    <title>RHSA-2026:48126 — Red Hat Security Advisory: Red Hat Developer Hub 1.10.3 Plugin Catalog GA plugins release.</title>
    <updated>2026-10-03T06:40:52.586423+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>multer: Multer: Denial of Service via aborted or malformed multipart uploads multer: Multer: Denial of Service via deeply nested field names in multipart form data brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization protobufjs: protobufjs: Denial of Service via crafted JSON descriptors js-cookie: JavaScript Cookie: Cookie attribute manipulation via prototype pollution grpc-js: @grpc/grpc-js: Server crash via malformed HTTP/2 stream initiation grpc-js: @grpc/grpc-js: Client or server crash via malformed compressed message linkify-it: linkify-it: Denial of Service via algorithmic complexity vulnerability dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution js-yaml: js-yaml: Denial of Service via crafted YAML documents protobufjs: protobufjs: Denial of Service via crafted .proto schema</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:48126"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2488</id>
    <title>WID-SEC-W-2026-2488 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
    <updated>2026-10-03T06:40:52.586454+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, und um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2488"/>
  </entry>
</feed>
