<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T16:13:41.429365+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1256</id>
    <title>certfr-2026-avi-1256 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T16:13:41.779375+00:00</updated>
    <content>certfr-2026-avi-1256</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1256"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-uq32454</id>
    <title>CLEANSTART-2026-UQ32454 — Security fix for CVE-2026-67314 applied in: n8n 2.28.0-r2</title>
    <updated>2026-10-02T16:13:41.779438+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: n8n</p>
<p>Security vulnerability affects the n8n package. This issue is resolved in later releases. See references for vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-uq32454"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-343828</id>
    <title>EUVD-2026-343828</title>
    <updated>2026-10-02T16:13:41.779470+00:00</updated>
    <content>EUVD-2026-343828</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-343828"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-67314</id>
    <title>fkie_cve-2026-67314</title>
    <updated>2026-10-02T16:13:41.779485+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>axios versions &gt;=1.15.2 and &lt;1.18.0 contain prototype-pollution read-side gadgets in Basic auth subfield handling (lib/adapters/http.js and lib/helpers/resolveConfig.js). When an application is already affected by a separate prototype-pollution primitive and makes an axios request with an own auth object that omits the username and/or password properties, axios reads the inherited Object.prototype.username and Object.prototype.password values and uses them to construct an outbound 'Authorization: Basic ...' header. axios itself does not pollute prototypes. The practical impact is outbound request tampering: an attacker who controls the polluted prototype values can inject attacker-chosen Basic auth credentials or replace an existing Authorization header. Credential disclosure is only possible under additional application-specific conditions.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-67314"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xj6q-8x83-jv6g</id>
    <title>GHSA-xj6q-8x83-jv6g — Axios: Prototype pollution auth subfields can inject Basic auth</title>
    <updated>2026-10-02T16:13:41.779512+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: axios</p>
<p>## Summary</p>
<p>Axios versions after the `GHSA-q8qp-cvcw-x6jj` fix still contain prototype-pollution read-side gadgets in Basic auth subfield handling. If a host application is already affected by prototype pollution and then makes an axios request with an own `auth` object that omits `username` or `password`, axios reads inherited `Object.prototype.username` and `Object.prototype.password` values and uses them to construct an outbound `Authorization: Basic ...` header.</p>
<p>This does not mean axios itself pollutes prototypes. Exploitation requires a separate prototype-pollution primitive in the host process, plus an axios call pattern such as `auth: opts.auth || {}`.</p>
<p>## Impact</p>
<p>An attacker who can pollute `Object.prototype.username` and/or `Object.prototype.password` can influence the Basic auth header on affected axios requests that pass an empty or partial own `auth` object.</p>
<p>The practical impact is outbound request tampering. The attacker can inject attacker-chosen Basic auth credentials, replace an existing `Authorization` header because axios removes it when `auth` is used, or cause downstream authorization failures.</p>
<p>This should not be described as automatic credential exfiltration. In the minimal reproduced case, the Basic auth values are attacker-controlled values, not secrets read from axios. Credential disclosure requires an additional application-specific condition, such as a request destination observable by the attacker and a partial real auth object with a missing po…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xj6q-8x83-jv6g"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:48758</id>
    <title>RHSA-2026:48758 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
    <updated>2026-10-02T16:13:41.779614+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>pyOpenSSL: DTLS cookie callback buffer overflow joserfc: joserfc: JWT Malleability via Non-Standard Padding axios: axios: Denial of Service via uncontrolled recursion in form data processing axios: axios: Outbound Request Tampering via Prototype Pollution in Basic Auth axios: axios: Information disclosure via Prototype Pollution in Node HTTP adapter axios: axios: Denial of Service via object serialization bypass nanoid: nanoid: Predictable ID generation due to integer overflow</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:48758"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-67314</id>
    <title>UBUNTU-CVE-2026-67314</title>
    <updated>2026-10-02T16:13:41.779643+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:20.04:LTS: node-axios, Ubuntu:Pro:22.04:LTS: node-axios, Ubuntu:Pro:24.04:LTS: node-axios, Ubuntu:Pro:26.04:LTS: node-axios</p>
<p>axios versions &gt;=1.15.2 and &lt;1.18.0 contain prototype-pollution read-side gadgets in Basic auth subfield handling (lib/adapters/http.js and lib/helpers/resolveConfig.js). When an application is already affected by a separate prototype-pollution primitive and makes an axios request with an own auth object that omits the username and/or password properties, axios reads the inherited Object.prototype.username and Object.prototype.password values and uses them to construct an outbound 'Authorization: Basic ...' header. axios itself does not pollute prototypes. The practical impact is outbound request tampering: an attacker who controls the polluted prototype values can inject attacker-chosen Basic auth credentials or replace an existing Authorization header. Credential disclosure is only possible under additional application-specific conditions.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-67314"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2958</id>
    <title>WID-SEC-W-2026-2958 — IBM License Metric Tool: Mehrere Schwachstellen</title>
    <updated>2026-10-02T16:13:41.779674+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM License Metric Tool ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2958"/>
  </entry>
</feed>
