<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T02:36:06.889718+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:35841</id>
    <title>ALSA-2026:35841 — Important: nodejs24 security, bug fix, and enhancement update</title>
    <updated>2026-10-03T02:36:06.939861+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: nodejs24, AlmaLinux:10: nodejs24-devel, AlmaLinux:10: nodejs24-docs, AlmaLinux:10: nodejs24-full-i18n, AlmaLinux:10: nodejs24-libs, AlmaLinux:10: nodejs24-npm</p>
<p>Node.js is a platform built on Chrome's JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices.</p>
<p>Security Fix(es):</p>
<p>* ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input (CVE-2026-42338)
  * undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (CVE-2026-12151)
  * undici: Undici: Information disclosure due to improper cache-control header parsing (CVE-2026-9678)
  * undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery. (CVE-2026-6733)
  * undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header (CVE-2026-11525)
  * undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy (CVE-2026-9697)
  * undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing (CVE-2026-6734)
  * nodejs: Node.js: Denial of Service via unlimited HTTP/2 ORIGIN frames (CVE-2026-48619)
  * nodejs: Node.js: Silent authority rebinding due to embedded-nul hostnames in TLS handling (CVE-2026-48930)
  * nodejs: Node.js: Unauthorized file metadata modification (CVE-2026-48935)
  * nodejs: Node.js WebCrypto: Denial of Service via large input to subtle.encrypt()…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:35841"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</id>
    <title>certfr-2026-avi-1094 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T02:36:06.939964+00:00</updated>
    <content>certfr-2026-avi-1094</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-id18571</id>
    <title>Withdrawn: CLEANSTART-2026-ID18571 — brace-expansion through 5</title>
    <updated>2026-10-03T02:36:06.939987+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: npm</p>
<p>Multiple security vulnerabilities affect the npm package. brace-expansion through 5. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-id18571"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-328307</id>
    <title>EUVD-2026-328307</title>
    <updated>2026-10-03T02:36:06.940011+00:00</updated>
    <content>EUVD-2026-328307</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-328307"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-6733</id>
    <title>fkie_cve-2026-6733</title>
    <updated>2026-10-03T02:36:06.940024+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Impact:
Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HTTP/1.1 response onto an idle socket after a request completes. When the client dispatches the next request on that socket, it associates the injected response with the new request, causing responses to be delivered to the wrong requests.</p>
<p>This requires an attacker-controlled or compromised upstream HTTP/1.1 server and keep-alive connection reuse.</p>
<p>Patches:
Upgrade to undici v6.26.0, v7.28.0 or v8.5.0.</p>
<p>Workarounds:
Disable keep-alive connection reuse by setting keepAliveTimeout: 0 on the Client or Pool.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-6733"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-35p6-xmwp-9g52</id>
    <title>GHSA-35p6-xmwp-9g52 — undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse</title>
    <updated>2026-10-03T02:36:06.940051+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: undici</p>
<p>## Impact</p>
<p>Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HTTP/1.1 response onto an idle socket after a request completes. When the client dispatches the next request on that socket, it associates the injected response with the new request, causing responses to be delivered to the wrong requests.</p>
<p>This requires an attacker-controlled or compromised upstream HTTP/1.1 server and keep-alive connection reuse.</p>
<p>## Patches</p>
<p>Upgrade to undici v6.27.0, v7.28.0 or v8.5.0.</p>
<p>## Workarounds</p>
<p>Disable keep-alive connection reuse by setting `keepAliveTimeout: 0` on the Client or Pool.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-35p6-xmwp-9g52"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11121-1</id>
    <title>openSUSE-SU-2026:11121-1 — corepack24-24.17.0-1.1 on GA media</title>
    <updated>2026-10-03T02:36:06.940081+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>corepack24-24.17.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11121-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:38009</id>
    <title>RHSA-2026:38009 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-03T02:36:06.940110+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery. undici: undici vulnerable to HTTP header injection via Set-Cookie percent-decoding undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:38009"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:35841</id>
    <title>RLSA-2026:35841 — Important: nodejs24 security, bug fix, and enhancement update</title>
    <updated>2026-10-03T02:36:06.940131+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: nodejs24</p>
<p>Node.js is a platform built on Chrome's JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices.</p>
<p>Security Fix(es):</p>
<p>* ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input (CVE-2026-42338)</p>
<p>* undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (CVE-2026-12151)</p>
<p>* undici: Undici: Information disclosure due to improper cache-control header parsing (CVE-2026-9678)</p>
<p>* undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery. (CVE-2026-6733)</p>
<p>* undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header (CVE-2026-11525)</p>
<p>* undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy (CVE-2026-9697)</p>
<p>* undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing (CVE-2026-6734)</p>
<p>* nodejs: Node.js: Denial of Service via unlimited HTTP/2 ORIGIN frames (CVE-2026-48619)</p>
<p>* nodejs: Node.js: Silent authority rebinding due to embedded-nul hostnames in TLS handling (CVE-2026-48930)</p>
<p>* nodejs: Node.js: Unauthorized file metadata modification (CVE-2026-48935)</p>
<p>* nodejs: Node.js WebCrypto: Denial of Service via large input to subtle.encrypt() (CVE-2026-48933…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:35841"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22368-1</id>
    <title>SUSE-SU-2026:22368-1 — Security update for nodejs22</title>
    <updated>2026-10-03T02:36:06.940171+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for nodejs22</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22368-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-6733</id>
    <title>UBUNTU-CVE-2026-6733</title>
    <updated>2026-10-03T02:36:06.940198+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:24.04:LTS: node-undici, Ubuntu:25.10: node-undici, Ubuntu:26.04:LTS: node-undici</p>
<p>Impact: Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HTTP/1.1 response onto an idle socket after a request completes. When the client dispatches the next request on that socket, it associates the injected response with the new request, causing responses to be delivered to the wrong requests. This requires an attacker-controlled or compromised upstream HTTP/1.1 server and keep-alive connection reuse. Patches: Upgrade to undici v6.26.0, v7.28.0 or v8.5.0. Workarounds: Disable keep-alive connection reuse by setting keepAliveTimeout: 0 on the Client or Pool.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-6733"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2618</id>
    <title>WID-SEC-W-2026-2618 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
    <updated>2026-10-03T02:36:06.940223+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, und um Daten zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2618"/>
  </entry>
</feed>
