<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T13:40:45.407910+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0958</id>
    <title>certfr-2026-avi-0958 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T13:40:45.416827+00:00</updated>
    <content>certfr-2026-avi-0958</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0958"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-327294</id>
    <title>EUVD-2026-327294</title>
    <updated>2026-10-02T13:40:45.416865+00:00</updated>
    <content>EUVD-2026-327294</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-327294"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-5079</id>
    <title>fkie_cve-2026-5079</title>
    <updated>2026-10-02T13:40:45.416879+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Impact: multer versions 1.0.0 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service via deeply nested field names in multipart form data. The append-field dependency parses bracket notation in field names with no limit on nesting depth, allowing an attacker to force allocation of deeply nested object structures that consume CPU and memory. A single HTTP request with a crafted multipart body is sufficient to exploit this.</p>
<p>Patches: Users should upgrade to multer 2.2.0 (2.x line) or 3.0.0-alpha.2 (3.x prerelease) and configure the new limits.fieldNestingDepth option to the minimum depth their application requires.</p>
<p>Workarounds: Set limits.fields to a reasonable value to reduce the number of fields an attacker can send per request. This does not fully mitigate the issue but limits the impact.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-5079"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-72gw-mp4g-v24j</id>
    <title>GHSA-72gw-mp4g-v24j — Multer vulnerable to Denial of Service via deeply nested field names</title>
    <updated>2026-10-02T13:40:45.416911+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: multer</p>
<p>### Impact</p>
<p>Multer is vulnerable to a Denial of Service (DoS) via deeply nested field names in multipart form data. The `append-field` dependency parses bracket notation in field names (e.g., `a[b][c]`) with no limit on nesting depth, allowing an attacker to force allocation of deeply nested object structures that consume CPU and memory. A single HTTP request with a crafted multipart body is sufficient to exploit this.</p>
<p>### Patches</p>
<p>Users should upgrade to `2.2.0` and configure `limits.fieldNestingDepth` to the minimum depth their application requires.</p>
<p>### Workarounds</p>
<p>Set `limits.fields` to a reasonable value to reduce the number of fields an attacker can send per request. This does not fully mitigate the issue but limits the impact.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-72gw-mp4g-v24j"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:48126</id>
    <title>RHSA-2026:48126 — Red Hat Security Advisory: Red Hat Developer Hub 1.10.3 Plugin Catalog GA plugins release.</title>
    <updated>2026-10-02T13:40:45.416940+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>multer: Multer: Denial of Service via aborted or malformed multipart uploads multer: Multer: Denial of Service via deeply nested field names in multipart form data brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization protobufjs: protobufjs: Denial of Service via crafted JSON descriptors js-cookie: JavaScript Cookie: Cookie attribute manipulation via prototype pollution grpc-js: @grpc/grpc-js: Server crash via malformed HTTP/2 stream initiation grpc-js: @grpc/grpc-js: Client or server crash via malformed compressed message linkify-it: linkify-it: Denial of Service via algorithmic complexity vulnerability dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution js-yaml: js-yaml: Denial of Service via crafted YAML documents protobufjs: protobufjs: Denial of Service via crafted .proto schema</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:48126"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2488</id>
    <title>WID-SEC-W-2026-2488 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
    <updated>2026-10-02T13:40:45.416971+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, und um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2488"/>
  </entry>
</feed>
