<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T14:07:47.860308+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0958</id>
    <title>certfr-2026-avi-0958 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T14:07:47.954400+00:00</updated>
    <content>certfr-2026-avi-0958</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0958"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-jr64129</id>
    <title>Withdrawn: CLEANSTART-2026-JR64129 — Security fixes in renovate 44.32.4-r1</title>
    <updated>2026-10-03T14:07:47.954442+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: renovate</p>
<p>Package renovate version 44.32.4-r1 fixes 27 vulnerabilities: CVE-2026-59873, CVE-2026-59874, CVE-2026-59871, CVE-2026-59875, ghsa-r292-9mhp-454m...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-jr64129"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-335279</id>
    <title>EUVD-2026-335279</title>
    <updated>2026-10-03T14:07:47.954474+00:00</updated>
    <content>EUVD-2026-335279</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-335279"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-59875</id>
    <title>fkie_cve-2026-59875</title>
    <updated>2026-10-03T14:07:47.954488+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX path and linkpath records in src/pax.ts, allowing a crafted archive with values to reach fs.lstat or fs.open and terminate the process with an uncaught exception. This issue is fixed in version 7.5.17.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-59875"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gvwx-54wh-qm9j</id>
    <title>GHSA-gvwx-54wh-qm9j — node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records</title>
    <updated>2026-10-03T14:07:47.954511+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: tar</p>
<p>## Summary</p>
<p>`node-tar` strips trailing `NUL` bytes from long-name (`L`) and long-linkpath (`K`) GNU extended headers but does **not** apply the same sanitization to equivalent fields delivered via PAX (`x` typeflag) extended headers. A PAX record of the form `path=visible.txt\x00hidden.txt` is parsed verbatim into `entry.path` and flows into `fs.lstat()` / `fs.open()`, which Node.js core rejects with `ERR_INVALID_ARG_VALUE`. The throw originates inside an `FSReqCallback` async chain that is **not** wrapped by the consumer's `await/try-catch` around `tar.x()` — it surfaces as `uncaughtException` and terminates the process.</p>
<p>This is a remote denial-of-service primitive against any process that extracts attacker-supplied tarballs through `tar.x` / `tar.extract` / `tar.t` / `tar.Parser`, even when the consumer follows the documented `try/catch` error-handling pattern.</p>
<p>A secondary parser-differential (CWE-436) exists because `tar(1)`, `bsdtar`, and Python `tarfile` truncate the path at the first `NUL` (yielding `visible.txt`) while node-tar retains the full string. A validator that pre-scans a tarball with one tool and extracts with the other is bypassed.</p>
<p>---</p>
<p>## Root cause</p>
<p>### Vulnerable sink — `src/pax.ts:157-183`</p>
<p>PAX KV records flow through `parseKVLine`. The value half (`v`) is assigned directly to the result object with no sanitization for embedded NUL bytes:</p>
<p>```ts
// src/pax.ts:157
const parseKVLine = (set: Record&lt;string, unknown&gt;, line: string) =&gt; {
  const n = parseI…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gvwx-54wh-qm9j"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-59875</id>
    <title>msrc_CVE-2026-59875 — node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records</title>
    <updated>2026-10-03T14:07:47.954590+00:00</updated>
    <content>msrc_CVE-2026-59875</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-59875"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59875</id>
    <title>UBUNTU-CVE-2026-59875</title>
    <updated>2026-10-03T14:07:47.954607+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: node-tar, Ubuntu:Pro:16.04:LTS: node-tar, Ubuntu:18.04:LTS: node-tar, Ubuntu:Pro:20.04:LTS: node-tar, Ubuntu:22.04:LTS: node-tar, Ubuntu:24.04:LTS: node-tar, Ubuntu:25.10: node-tar, Ubuntu:26.04:LTS: node-tar</p>
<p>node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX path and linkpath records in src/pax.ts, allowing a crafted archive with values to reach fs.lstat or fs.open and terminate the process with an uncaught exception. This issue is fixed in version 7.5.17.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59875"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3621</id>
    <title>WID-SEC-W-2026-3621 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
    <updated>2026-10-03T14:07:47.954637+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Informationen offenzulegen, um einen Denial of Service Angriff durchzuführen, um Daten zu manipulieren und um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3621"/>
  </entry>
</feed>
