<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T00:53:57.202310+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-bg95605</id>
    <title>Withdrawn: CLEANSTART-2026-BG95605 — Security fixes in langfuse-worker 4.0.0-r1</title>
    <updated>2026-10-04T00:53:57.304320+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: langfuse-worker</p>
<p>Package langfuse-worker version 4.0.0-r1 fixes 24 vulnerabilities: ghsa-55q2-fjhq-7xh7, CVE-2026-18446, CVE-2026-69207, CVE-2026-71848, CVE-2026-71850...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-bg95605"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-349519</id>
    <title>EUVD-2026-349519</title>
    <updated>2026-10-04T00:53:57.304383+00:00</updated>
    <content>EUVD-2026-349519</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-349519"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-71848</id>
    <title>fkie_cve-2026-71848</title>
    <updated>2026-10-04T00:53:57.304400+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.0 to 4.12.33, the languageDetector middleware is vulnerable to algorithmic complexity denial of service when processing a crafted language tag containing a large number of hyphen separated subtags. To implement progressive language tag truncation, normalizeLanguage() repeatedly calls parts.slice(0, i).join('-') for every possible prefix, so the total amount of string processing grows quadratically with the number of subtags. Language values may come from a query parameter, cookie, Accept-Language header, or URL path, depending on the detector configuration, and the default detector order enables query string, cookie, and header detection, so applications using languageDetector() may expose this processing to unauthenticated requests. An attacker may repeatedly send requests containing long, hyphen separated language tags, causing excessive CPU consumption and preventing unrelated requests from being processed. This issue is fixed in version 4.12.34.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-71848"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-54fx-42gc-7vw4</id>
    <title>GHSA-54fx-42gc-7vw4 — Hono: Algorithmic Complexity DoS in Language Middleware</title>
    <updated>2026-10-04T00:53:57.304431+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: hono</p>
<p>### Summary</p>
<p>The `languageDetector` middleware is vulnerable to algorithmic complexity denial of service when processing a crafted language tag containing a large number of hyphen-separated subtags.</p>
<p>### Details</p>
<p>To implement progressive language-tag truncation, `normalizeLanguage()` repeatedly calls `parts.slice(0, i).join('-')` for every possible prefix. The total amount of string processing grows quadratically with the number of subtags.</p>
<p>Language values may come from a query parameter, cookie, `Accept-Language` header, or URL path, depending on the detector configuration. The default detector order enables query-string, cookie, and header detection, so applications using `languageDetector()` may expose this processing to unauthenticated requests.</p>
<p>Request-size limits reduce the maximum cost of a single request but do not eliminate the issue. Inputs accepted by common JavaScript runtimes can still cause noticeable synchronous event-loop blocking.</p>
<p>### Impact</p>
<p>An attacker may repeatedly send requests containing long, hyphen-separated language tags, causing excessive CPU consumption and preventing unrelated requests from being processed.</p>
<p>The practical impact depends on the runtime's request-size limits, reverse-proxy configuration, and the detectors enabled by the application.</p>
<p>### Resolution</p>
<p>The progressive lookup should avoid reconstructing every shorter prefix. The implementation can instead inspect the configured supported languages and select the longest value that m…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-54fx-42gc-7vw4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3221</id>
    <title>WID-SEC-W-2026-3221 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
    <updated>2026-10-04T00:53:57.304475+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder Denial-of-Service-Zustände herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3221"/>
  </entry>
</feed>
