<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T12:27:32.575305+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-hr55516</id>
    <title>CLEANSTART-2026-HR55516 — nanoid is a secure, URL-friendly, unique string ID generator for JavaScript</title>
    <updated>2026-10-02T12:27:33.077906+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: qdrant</p>
<p>Security vulnerability affects the qdrant package. nanoid is a secure, URL-friendly, unique string ID generator for JavaScript.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-hr55516"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-351488</id>
    <title>EUVD-2026-351488</title>
    <updated>2026-10-02T12:27:33.078009+00:00</updated>
    <content>EUVD-2026-351488</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-351488"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-73086</id>
    <title>fkie_cve-2026-73086</title>
    <updated>2026-10-02T12:27:33.078027+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>nanoid is a secure, URL-friendly, unique string ID generator for JavaScript. Prior to versions 3.3.12 and 5.1.11, the nanoid(size) function in index.js and index.cjs coerces the user-influenced size parameter to a signed 32-bit integer, allowing a value of 2147483648 to become -2147483648 and corrupt the process-wide CSPRNG poolOffset in fillPool(), which causes subsequent session tokens, CSRF tokens, API keys, and unique identifiers to become the deterministic string "uuuuuuuuuuuuuuuuuuuuu" until the process restarts. This issue is fixed in versions 3.3.12 and 5.1.11.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-73086"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xwg4-73v4-xw9w</id>
    <title>GHSA-xwg4-73v4-xw9w — nanoid: Integer Overflow or Wraparound</title>
    <updated>2026-10-02T12:27:33.078056+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: nanoid</p>
<p>### Summary</p>
<p>An integer overflow in `nanoid(size)` permanently corrupts the process-wide CSPRNG pool, causing all subsequent ID generation to return the deterministic string `"uuuuuuuuuuuuuuuuuuuuu"`. Any application that passes user-influenced values to the `size` parameter loses all randomness guarantees for session tokens, CSRF tokens, and unique identifiers until process restart.</p>
<p>### Details</p>
<p>`nanoid()` at [`index.js:101`](https://github.com/ai/nanoid/blob/main/index.js#L101) coerces the `size` parameter with `size |= 0`, which converts it to a signed 32-bit integer. When `size &gt;= 2^31` (e.g., `2147483648`), this wraps to `-2147483648`.</p>
<p>The negative value is passed to `fillPool()` ([`index.js:15`](https://github.com/ai/nanoid/blob/main/index.js#L15)):</p>
<p>```javascript
function fillPool(bytes) {
  if (!pool || pool.length &lt; bytes) {       // false: pool exists, -2B &lt; pool.length
    pool = Buffer.allocUnsafe(bytes * POOL_SIZE_MULTIPLIER)
    crypto.getRandomValues(pool)
    poolOffset = 0
  } else if (poolOffset + bytes &gt; pool.length) {  // false: poolOffset + (-2B) &lt; pool.length
    crypto.getRandomValues(pool)
    poolOffset = 0
  }
  poolOffset += bytes  // poolOffset += -2147483648 → deeply negative
}
```</p>
<p>Neither branch triggers, so the pool is never refreshed. `poolOffset` becomes ~-2.1 billion.</p>
<p>Subsequent `nanoid()` calls execute:
```javascript
for (let i = poolOffset - size; i &lt; poolOffset; i++) {
  id += scopedUrlAlphabet[pool[i] &amp; 63]
}
```</p>
<p>`pool[negative_inde…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xwg4-73v4-xw9w"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11680-1</id>
    <title>openSUSE-SU-2026:11680-1 — agama-web-ui-24+0.a836cced5-52.1 on GA media</title>
    <updated>2026-10-02T12:27:33.078111+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>agama-web-ui-24+0.a836cced5-52.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11680-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:48758</id>
    <title>RHSA-2026:48758 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
    <updated>2026-10-02T12:27:33.078141+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>pyOpenSSL: DTLS cookie callback buffer overflow joserfc: joserfc: JWT Malleability via Non-Standard Padding axios: axios: Denial of Service via uncontrolled recursion in form data processing axios: axios: Outbound Request Tampering via Prototype Pollution in Basic Auth axios: axios: Information disclosure via Prototype Pollution in Node HTTP adapter axios: axios: Denial of Service via object serialization bypass nanoid: nanoid: Predictable ID generation due to integer overflow</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:48758"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-73086</id>
    <title>UBUNTU-CVE-2026-73086</title>
    <updated>2026-10-02T12:27:33.078169+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: node-mocha, Ubuntu:18.04:LTS: node-mocha, Ubuntu:20.04:LTS: node-mocha, Ubuntu:20.04:LTS: node-postcss, Ubuntu:22.04:LTS: node-postcss, Ubuntu:24.04:LTS: node-postcss, Ubuntu:26.04:LTS: node-postcss</p>
<p>nanoid is a secure, URL-friendly, unique string ID generator for JavaScript. Prior to versions 3.3.12 and 5.1.11, the nanoid(size) function in index.js and index.cjs coerces the user-influenced size parameter to a signed 32-bit integer, allowing a value of 2147483648 to become -2147483648 and corrupt the process-wide CSPRNG poolOffset in fillPool(), which causes subsequent session tokens, CSRF tokens, API keys, and unique identifiers to become the deterministic string "uuuuuuuuuuuuuuuuuuuuu" until the process restarts. This issue is fixed in versions 3.3.12 and 5.1.11.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-73086"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3376</id>
    <title>WID-SEC-W-2026-3376 — Atlassian Bamboo, Bitbucket, Confluence, Fisheye/Crucible, Jira Software und Jira Service Management: Mehrere Schwachst…</title>
    <updated>2026-10-02T12:27:33.078209+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Bitbucket, Confluence, Fisheye/Crucible, Jira Software und Jira Service Management ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, serverseitige Request-Forgery-Angriffe (SSRF) durchzuführen, Cross-Site-Scripting-Angriffe zu starten, sensible Informationen offenzulegen, Daten zu manipulieren oder Denial-of-Service-Zustände herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3376"/>
  </entry>
</feed>
