<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:54:12.497142+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:52841</id>
    <title>ALSA-2026:52841 — Important: nodejs-nodemon security update</title>
    <updated>2026-10-02T14:54:13.250520+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: nodejs-nodemon</p>
<p>Simple monitor script for use during development of a node.js app. For use during development of a node.js based application. nodemon will watch the files in the directory in which nodemon was started, and if any files change, nodemon will automatically restart your node application. nodemon does not require any changes to your code or method of development. nodemon simply wraps your node application and keeps an eye on any files that have changed. Remember that nodemon is a replacement wrapper for node, think of it as replacing the word "node" on the command line when you run your script.</p>
<p>Security Fix(es):</p>
<p>* brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays (CVE-2026-69152)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:52841"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165</id>
    <title>certfr-2026-avi-1165 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T14:54:13.250633+00:00</updated>
    <content>certfr-2026-avi-1165</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ae26966</id>
    <title>CLEANSTART-2026-AE26966 — Security fix for CVE-2026-69152 applied in: argo-workflows 3.6.19-r7, langfuse-worker 3.224.0-r3, langfuse-worker 3.224…</title>
    <updated>2026-10-02T14:54:13.250656+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: argo-workflows, CleanStart: langfuse-worker, CleanStart: n8n, CleanStart: npm, CleanStart: pulumi, CleanStart: renovate</p>
<p>CVE-2026-69152 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ae26966"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-343962</id>
    <title>EUVD-2026-343962</title>
    <updated>2026-10-02T14:54:13.250696+00:00</updated>
    <content>EUVD-2026-343962</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-343962"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-69152</id>
    <title>fkie_cve-2026-69152</title>
    <updated>2026-10-02T14:54:13.250710+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-69152"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rgw5-rvv9-x895</id>
    <title>GHSA-rgw5-rvv9-x895 — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation</title>
    <updated>2026-10-02T14:54:13.250733+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: brace-expansion</p>
<p>### Summary</p>
<p>The `maxLength` mitigation added in `5.0.8` for GHSA-mh99-v99m-4gvg / CVE-2026-14257 is incomplete. It bounds the accumulator where results are *combined*, but not the intermediate arrays that feed it. A ~25 KB input still crashes the Node process with an **uncatchable** out-of-memory error, so `try/catch` around `expand()` does not help.</p>
<p>A second, related path in the same function lets a ~400 KB input block the event loop for over two minutes without ever exceeding the memory bound.</p>
<p>### Details</p>
<p>`maxLength` was enforced in `combine()`, the single place output grows. Two arrays are built *before* `combine()` runs, and neither was bounded.</p>
<p>**1. Comma alternatives accumulate without a running total (memory exhaustion)**</p>
<p>Each alternative in `{a,b,c,...}` is expanded by its own recursive `expand_()` call, so each receives a full, independent `maxLength` allowance. The results were then concatenated into a single `values` array with no cumulative limit:</p>
<p>```js
values = []
for (let j = 0; j &lt; n.length; j++) {
  values.push.apply(values, expand_(n[j], max, maxLength, false))
}</p>
<p>acc = combine(acc, pre, values, max, maxLength, ...)
```</p>
<p>With `A` alternatives, `values` can reach `A * maxLength` characters before `combine()` gets a chance to truncate it. At the default `maxLength` of 4,000,000 and 400 alternatives, that is well past any default heap.</p>
<p>**2. Padded sequences ignore `maxLength` while generating (CPU exhaustion)**</p>
<p>`expandSequence()` was bounded by `max` (…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rgw5-rvv9-x895"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-69152</id>
    <title>msrc_CVE-2026-69152 — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation</title>
    <updated>2026-10-02T14:54:13.250788+00:00</updated>
    <content>msrc_CVE-2026-69152</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-69152"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0325</id>
    <title>NCSC-2026-0325 — Kwetsbaarheden verholpen in Atlassian producten</title>
    <updated>2026-10-02T14:54:13.250805+00:00</updated>
    <content>NCSC-2026-0325</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0325"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:50079</id>
    <title>RHSA-2026:50079 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
    <updated>2026-10-02T14:54:13.250923+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation postcss: PostCSS: Information disclosure via crafted sourceMappingURL</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:50079"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:52841</id>
    <title>RHSA-2026:52841 — Red Hat Security Advisory: nodejs-nodemon security update</title>
    <updated>2026-10-02T14:54:13.250942+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:52841"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:52841</id>
    <title>RLSA-2026:52841 — Important: nodejs-nodemon security update</title>
    <updated>2026-10-02T14:54:13.250959+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: nodejs-nodemon</p>
<p>Simple monitor script for use during development of a node.js app.  For use during development of a node.js based application.  nodemon will watch the files in the directory in which nodemon was started, and if any files change, nodemon will automatically restart your node application.  nodemon does not require any changes to your code or method of development. nodemon simply wraps your node application and keeps an eye on any files that have changed. Remember that nodemon is a replacement wrapper for node, think of it as replacing the word "node" on the command line when you run your script.</p>
<p>Security Fix(es):</p>
<p>* brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays (CVE-2026-69152)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:52841"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-69152</id>
    <title>UBUNTU-CVE-2026-69152</title>
    <updated>2026-10-02T14:54:13.250985+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: node-brace-expansion, Ubuntu:20.04:LTS: node-brace-expansion, Ubuntu:22.04:LTS: node-brace-expansion, Ubuntu:24.04:LTS: node-brace-expansion, Ubuntu:26.04:LTS: node-brace-expansion</p>
<p>The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-69152"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2725</id>
    <title>WID-SEC-W-2026-2725 — Red Hat Enterprise Linux (brace-expansion): Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-02T14:54:13.251012+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2725"/>
  </entry>
</feed>
