<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T23:55:38.345661+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-10873</id>
    <title>bdu:2026-10873</title>
    <updated>2026-10-02T23:55:38.358947+00:00</updated>
    <content>bdu:2026-10873</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-10873"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0788</id>
    <title>certfr-2026-avi-0788 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T23:55:38.358980+00:00</updated>
    <content>certfr-2026-avi-0788</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0788"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-gy63167</id>
    <title>Withdrawn: CLEANSTART-2026-GY63167 — Security fixes in thingsboard 4.3.1.3-r1</title>
    <updated>2026-10-02T23:55:38.358998+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: thingsboard</p>
<p>Package thingsboard version 4.3.1.3-r1 fixes 82 vulnerabilities: ghsa-r29c-68gh-xp6x, ghsa-h6fc-48rj-7qqh, ghsa-5m62-pw8w-7w9f, ghsa-gx5v-xp9w-j4cg, ghsa-fv25-8xcx-gqjc...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-gy63167"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-319224</id>
    <title>EUVD-2026-319224</title>
    <updated>2026-10-02T23:55:38.359025+00:00</updated>
    <content>EUVD-2026-319224</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-319224"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-8723</id>
    <title>fkie_cve-2026-8723</title>
    <updated>2026-10-02T23:55:38.359037+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>### Summary</p>
<p>`qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs's null-related options (`skipNulls`, `strictNullHandling`).</p>
<p>### Details</p>
<p>In the comma + `encodeValuesOnly` branch, `lib/stringify.js:145` mapped the array through the raw encoder before joining:</p>
<p>```js</p>
<p>obj = utils.maybeMap(obj, encoder);</p>
<p>```</p>
<p>`utils.encode` (`lib/utils.js:195`) reads `str.length` with no null guard, so a `null` or `undefined` element throws `TypeError`. `skipNulls` and `strictNullHandling` are both checked in the per-element loop below this line and never get a chance to run.</p>
<p>Same class of bug as the filter-array path fixed in 0c180a4. The vulnerable shape of the comma + `encodeValuesOnly` branch was introduced in 4c4b23d ("encode comma values more consistently", PR #463, 2023-01-19), first released in v6.11.1.</p>
<p>#### PoC</p>
<p>```js</p>
<p>const qs = require('qs');</p>
<p>qs.stringify({ a: [null, 'b'] },      { arrayFormat: 'comma', encodeValuesOnly: true });</p>
<p>qs.stringify({ a: [undefined, 'b'] }, { arrayFormat: 'comma', encodeValuesOnly: true });</p>
<p>qs.stringify({ a: [null] },           { arrayFormat: 'comma', encodeValuesOnly: true });</p>
<p>// TypeError: Cannot read properties of null (reading 'length')</p>
<p>//     at encode (lib/utils.js:195:13)</p>
<p>//     at Object.maybeMap (lib/utils.js:322:37)</p>
<p>//     at stringify (lib/stringify.j…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-8723"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-q8mj-m7cp-5q26</id>
    <title>GHSA-q8mj-m7cp-5q26 — qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/undefined entries in comma-format arrays…</title>
    <updated>2026-10-02T23:55:38.359096+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: qs</p>
<p>### Summary</p>
<p>`qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs's null-related options (`skipNulls`, `strictNullHandling`).</p>
<p>### Details</p>
<p>In the comma + `encodeValuesOnly` branch, `lib/stringify.js:145` mapped the array through the raw encoder before joining:</p>
<p>```js
obj = utils.maybeMap(obj, encoder);
```</p>
<p>`utils.encode` (`lib/utils.js:195`) reads `str.length` with no null guard, so a `null` or `undefined` element throws `TypeError`. `skipNulls` and `strictNullHandling` are both checked in the per-element loop below this line and never get a chance to run.</p>
<p>Same class of bug as the filter-array path fixed in 0c180a4. The vulnerable shape of the comma + `encodeValuesOnly` branch was introduced in 4c4b23d ("encode comma values more consistently", PR #463, 2023-01-19), first released in v6.11.1.</p>
<p>#### PoC</p>
<p>```js
const qs = require('qs');</p>
<p>qs.stringify({ a: [null, 'b'] },      { arrayFormat: 'comma', encodeValuesOnly: true });
qs.stringify({ a: [undefined, 'b'] }, { arrayFormat: 'comma', encodeValuesOnly: true });
qs.stringify({ a: [null] },           { arrayFormat: 'comma', encodeValuesOnly: true });
// TypeError: Cannot read properties of null (reading 'length')
//     at encode (lib/utils.js:195:13)
//     at Object.maybeMap (lib/utils.js:322:37)
//     at stringify (lib/stringify.js:145:25)
```</p>
<p>#### Fix</p>
<p>`lib/stringify.js:14…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-q8mj-m7cp-5q26"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-8723</id>
    <title>msrc_CVE-2026-8723 — qs.stringify crashes on null/undefined entries in comma-format arrays under encodeValuesOnly</title>
    <updated>2026-10-02T23:55:38.359147+00:00</updated>
    <content>msrc_CVE-2026-8723</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-8723"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:17682</id>
    <title>RHSA-2026:17682 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-02T23:55:38.359163+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>qs: qs: Denial of Service due to improper handling of null/undefined array elements dotnet: .NET: infinite loop allows an attacker to cause a denial of service brace-expansion: brace-expansion: Denial of Service due to excessive memory allocation when expanding large numeric ranges</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:17682"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-8723</id>
    <title>UBUNTU-CVE-2026-8723</title>
    <updated>2026-10-02T23:55:38.359181+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: node-qs, Ubuntu:16.04:LTS: node-qs, Ubuntu:18.04:LTS: node-qs, Ubuntu:Pro:20.04:LTS: node-qs, Ubuntu:22.04:LTS: node-qs, Ubuntu:24.04:LTS: node-qs, Ubuntu:25.10: node-qs, Ubuntu:26.04:LTS: node-qs</p>
<p>### Summary `qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs's null-related options (`skipNulls`, `strictNullHandling`). ### Details In the comma + `encodeValuesOnly` branch, `lib/stringify.js:145` mapped the array through the raw encoder before joining: ```js obj = utils.maybeMap(obj, encoder); ``` `utils.encode` (`lib/utils.js:195`) reads `str.length` with no null guard, so a `null` or `undefined` element throws `TypeError`. `skipNulls` and `strictNullHandling` are both checked in the per-element loop below this line and never get a chance to run. Same class of bug as the filter-array path fixed in 0c180a4. The vulnerable shape of the comma + `encodeValuesOnly` branch was introduced in 4c4b23d ("encode comma values more consistently", PR #463, 2023-01-19), first released in v6.11.1. #### PoC ```js const qs = require('qs'); qs.stringify({ a: [null, 'b'] },      { arrayFormat: 'comma', encodeValuesOnly: true }); qs.stringify({ a: [undefined, 'b'] }, { arrayFormat: 'comma', encodeValuesOnly: true }); qs.stringify({ a: [null] },           { arrayFormat: 'comma', encodeValuesOnly: true }); // TypeError: Cannot read properties of null (reading 'length') //     at encode (lib/utils.js:195:13) //     at Object.maybeMap (lib/utils.js:322:37) //     at stringify (lib/stringify.js:145:25) ``` #### Fix `lib/stringify.js:145`, applied…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-8723"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2118</id>
    <title>WID-SEC-W-2026-2118 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
    <updated>2026-10-02T23:55:38.359246+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um einen Denial of Service Angriff durchzuführen, und um Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2118"/>
  </entry>
</feed>
