<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T11:22:15.350700+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1233</id>
    <title>certfr-2026-avi-1233 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T11:22:15.547193+00:00</updated>
    <content>certfr-2026-avi-1233</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1233"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-cl40927</id>
    <title>CLEANSTART-2026-CL40927 — undici's decompress interceptor decompresses response bodies according to the untrusted Content-Encoding header</title>
    <updated>2026-10-03T11:22:15.547253+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: langfuse</p>
<p>Security vulnerability affects the langfuse package. undici's decompress interceptor decompresses response bodies according to the untrusted Content-Encoding header.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-cl40927"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-364050</id>
    <title>EUVD-2026-364050</title>
    <updated>2026-10-03T11:22:15.547289+00:00</updated>
    <content>EUVD-2026-364050</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-364050"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-84890</id>
    <title>fkie_cve-2026-84890</title>
    <updated>2026-10-03T11:22:15.547302+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>undici's decompress interceptor decompresses response bodies according to the untrusted Content-Encoding header. While the number of content-encoding layers is capped, the total decompressed output size is unbounded and there is no configuration option to limit it. A malicious or faulty upstream can therefore return a small compressed payload, a compression bomb, that expands to hundreds of megabytes or more in client memory, an asymmetric resource consumption that can exhaust memory and crash the process. This affects undici versions from 7.15.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-84890"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3xpg-4rpp-hhhm</id>
    <title>GHSA-3xpg-4rpp-hhhm — undici vulnerable to Denial of Service via unbounded decompression of compressed responses</title>
    <updated>2026-10-03T11:22:15.547328+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: undici</p>
<p>### Impact</p>
<p>The `interceptors.decompress()` interceptor decompresses HTTP response bodies according to the untrusted `Content-Encoding` header. The number of decompression layers is capped at 5, but the total decompressed output size is not bounded and there is no option to limit it. A malicious or faulty upstream can return a small compressed payload (a compression bomb) that expands to hundreds of megabytes or gigabytes in client memory, exhausting memory and causing the Node.js process to crash or become unresponsive. Any application using the decompress interceptor to read responses from untrusted or compromised upstreams is affected.</p>
<p>### Patches</p>
<p>Upgrade to `7.29.1` or `8.10.2`. The interceptor now accepts a `maxSize` option (default 64 MiB) and rejects responses whose decompressed output exceeds it with a `ResponseExceededMaxSizeError`.</p>
<p>### Workarounds</p>
<p>Once upgraded, set a conservative `maxSize` on the interceptor. Before upgrading, avoid using `interceptors.decompress()` with untrusted upstreams, or apply a custom interceptor that enforces a decompressed output size limit.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3xpg-4rpp-hhhm"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:54389</id>
    <title>RHSA-2026:54389 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
    <updated>2026-10-03T11:22:15.547360+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function undici: undici: Denial of Service due to orphaned response body in retry handler brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation undici: undici: Denial of Service via unbounded decompression of compressed responses undici: undici: Cross-user cookie disclosure via Set-Cookie caching undici: Undici: Response truncation and connection termination undici: undici: Integrity failure due to caching of unsafe HTTP method responses undici: undici: Denial of Service via WebSocketStream unclean close undici: undici: Authentication bypass via cross-origin cache poisoning due to missing origin isolation</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:54389"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-84890</id>
    <title>UBUNTU-CVE-2026-84890</title>
    <updated>2026-10-03T11:22:15.547393+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:24.04:LTS: node-undici, Ubuntu:26.04:LTS: node-undici</p>
<p>undici's decompress interceptor decompresses response bodies according to the untrusted Content-Encoding header. While the number of content-encoding layers is capped, the total decompressed output size is unbounded and there is no configuration option to limit it. A malicious or faulty upstream can therefore return a small compressed payload, a compression bomb, that expands to hundreds of megabytes or more in client memory, an asymmetric resource consumption that can exhaust memory and crash the process. This affects undici versions from 7.15.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-84890"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596</id>
    <title>WID-SEC-W-2026-3596 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
    <updated>2026-10-03T11:22:15.547417+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um einen Cross-Site Scripting Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596"/>
  </entry>
</feed>
