<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T12:10:47.617856+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2023:5360</id>
    <title>ALSA-2023:5360 — Important: nodejs:16 security, bug fix, and enhancement update</title>
    <updated>2026-10-02T12:10:47.990147+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: nodejs, AlmaLinux:8: nodejs-devel, AlmaLinux:8: nodejs-docs, AlmaLinux:8: nodejs-full-i18n, AlmaLinux:8: nodejs-nodemon, AlmaLinux:8: nodejs-packaging, AlmaLinux:8: npm</p>
<p>Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.</p>
<p>The following packages have been upgraded to a later upstream version: nodejs (16). (BZ#2233891)</p>
<p>Security Fix(es):</p>
<p>* nodejs: Permissions policies can be bypassed via Module._load (CVE-2023-32002)
* nodejs-semver: Regular expression denial of service (CVE-2022-25883)
* nodejs: Permissions policies can impersonate other modules in using module.constructor.createRequire() (CVE-2023-32006)
* nodejs: Permissions policies can be bypassed via process.binding (CVE-2023-32559)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Bug Fix(es):</p>
<p>* nodejs:16/nodejs: nodejs.prov doesn't generate the bundled dependency for modules starting @ like @colors/colors (BZ#2237394)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2023:5360"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-04976</id>
    <title>bdu:2023-04976</title>
    <updated>2026-10-02T12:10:47.990230+00:00</updated>
    <content>bdu:2023-04976</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-04976"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0705</id>
    <title>certfr-2023-avi-0705 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
    <updated>2026-10-02T12:10:47.990256+00:00</updated>
    <content>certfr-2023-avi-0705</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0705"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-206311</id>
    <title>EUVD-2026-206311</title>
    <updated>2026-10-02T12:10:47.990273+00:00</updated>
    <content>EUVD-2026-206311</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-206311"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-25883</id>
    <title>fkie_cve-2022-25883</title>
    <updated>2026-10-02T12:10:47.990285+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-25883"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-c2qf-rxjj-qqgw</id>
    <title>GHSA-c2qf-rxjj-qqgw — semver vulnerable to Regular Expression Denial of Service</title>
    <updated>2026-10-02T12:10:47.990308+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: semver</p>
<p>Versions of the package semver before 7.5.2 on the 7.x branch, before 6.3.1 on the 6.x branch, and all other versions before 5.7.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-c2qf-rxjj-qqgw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-25883</id>
    <title>gsd-2022-25883</title>
    <updated>2026-10-02T12:10:47.990331+00:00</updated>
    <content>gsd-2022-25883</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-25883"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2022-25883</id>
    <title>msrc_CVE-2022-25883 — Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the func…</title>
    <updated>2026-10-02T12:10:47.990342+00:00</updated>
    <content>msrc_CVE-2022-25883</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2022-25883"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0034</id>
    <title>NCSC-2026-0034 — Kwetsbaarheden verholpen in Atlassian producten</title>
    <updated>2026-10-02T12:10:47.990359+00:00</updated>
    <content>NCSC-2026-0034</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0034"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14012-1</id>
    <title>openSUSE-SU-2024:14012-1 — system-user-velociraptor-1.0.0-9.1 on GA media</title>
    <updated>2026-10-02T12:10:47.990407+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>system-user-velociraptor-1.0.0-9.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:14012-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:4341</id>
    <title>RHSA-2023:4341 — Red Hat Security Advisory: Logging Subsystem 5.7.4 - Red Hat OpenShift bug fix and security update</title>
    <updated>2026-10-02T12:10:47.990423+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>nodejs-semver: Regular expression denial of service rubygem-activesupport: Regular Expression Denial of Service</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:4341"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-25883</id>
    <title>UBUNTU-CVE-2022-25883</title>
    <updated>2026-10-02T12:10:47.990441+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: node-semver, Ubuntu:Pro:16.04:LTS: node-semver, Ubuntu:18.04:LTS: node-semver, Ubuntu:20.04:LTS: node-semver, Ubuntu:22.04:LTS: node-semver, Ubuntu:24.04:LTS: node-semver, Ubuntu:25.10: node-semver, Ubuntu:26.04:LTS: node-semver</p>
<p>Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-25883"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2356</id>
    <title>WID-SEC-W-2023-2356 — IBM QRadar SIEM: Mehre Schwachstellen</title>
    <updated>2026-10-02T12:10:47.990469+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein anonymer Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2356"/>
  </entry>
</feed>
