<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T11:05:29.561198+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:18480</id>
    <title>ALSA-2026:18480 — Important: linux-sgx security update</title>
    <updated>2026-10-02T11:05:30.109458+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: sgx-common, AlmaLinux:10: sgx-libs, AlmaLinux:10: sgx-mpa, AlmaLinux:10: sgx-pccs, AlmaLinux:10: sgx-pccs-admin, AlmaLinux:10: sgx-pckid-tool, AlmaLinux:10: tdx-qgs</p>
<p>The Intel SGX SDK is a collection of APIs, libraries, documentations and tools that allow software developers to create and debug Intel SGX enabled applications in C/C++.</p>
<p>Security Fix(es):</p>
<p>* qs: qs: Denial of Service via improper input validation in array parsing (CVE-2025-15284)
  * node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives (CVE-2026-23745)
  * node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition (CVE-2026-23950)
  * lodash: prototype pollution in _.unset and _.omit functions (CVE-2025-13465)
  * node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check (CVE-2026-24842)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:18480"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-00332</id>
    <title>bdu:2026-00332</title>
    <updated>2026-10-02T11:05:30.109572+00:00</updated>
    <content>bdu:2026-00332</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-00332"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0065</id>
    <title>certfr-2026-avi-0065 — De multiples vulnérabilités ont été découvertes dans les produits Atlassian. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-02T11:05:30.109590+00:00</updated>
    <content>certfr-2026-avi-0065</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0065"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-267888</id>
    <title>EUVD-2026-267888</title>
    <updated>2026-10-02T11:05:30.109607+00:00</updated>
    <content>EUVD-2026-267888</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-267888"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-15284</id>
    <title>fkie_cve-2025-15284</title>
    <updated>2026-10-02T11:05:30.109618+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Improper Input Validation vulnerability in qs (parse modules) allows HTTP DoS.This issue affects qs: &lt; 6.14.1.</p>
<p>Summary</p>
<p>The arrayLimit option in qs did not enforce limits for bracket notation (a[]=1&amp;a[]=2), only for indexed notation (a[0]=1). This is a consistency bug; arrayLimit should apply uniformly across all array notations.</p>
<p>Note: The default parameterLimit of 1000 effectively mitigates the DoS scenario originally described. With default options, bracket notation cannot produce arrays larger than parameterLimit regardless of arrayLimit, because each a[]=valueconsumes one parameter slot. The severity has been reduced accordingly.</p>
<p>Details</p>
<p>The arrayLimit option only checked limits for indexed notation (a[0]=1&amp;a[1]=2) but did not enforce it for bracket notation (a[]=1&amp;a[]=2).</p>
<p>Vulnerable code (lib/parse.js:159-162):</p>
<p>if (root === '[]' &amp;&amp; options.parseArrays) {
    obj = utils.combine([], leaf);  // No arrayLimit check
}</p>
<p>Working code (lib/parse.js:175):</p>
<p>else if (index &lt;= options.arrayLimit) {  // Limit checked here
    obj = [];
    obj[index] = leaf;
}</p>
<p>The bracket notation handler at line 159 uses utils.combine([], leaf) without validating against options.arrayLimit, while indexed notation at line 175 checks index &lt;= options.arrayLimit before creating arrays.</p>
<p>PoC</p>
<p>const qs = require('qs');
const result = qs.parse('a[]=1&amp;a[]=2&amp;a[]=3&amp;a[]=4&amp;a[]=5&amp;a[]=6', { arrayLimit: 5 });
console.log(result.a.length);  // Output: 6 (should be max 5)</p>
<p>Note on parameterL…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-15284"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6rw7-vpxm-498p</id>
    <title>GHSA-6rw7-vpxm-498p — qs's arrayLimit bypass in its bracket notation allows DoS via memory exhaustion</title>
    <updated>2026-10-02T11:05:30.109670+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: qs</p>
<p>### Summary</p>
<p>The `arrayLimit` option in qs did not enforce limits for bracket notation (`a[]=1&amp;a[]=2`), only for indexed notation (`a[0]=1`). This is a consistency bug; `arrayLimit` should apply uniformly across all array notations.</p>
<p>**Note:** The default `parameterLimit` of 1000 effectively mitigates the DoS scenario originally described. With default options, bracket notation cannot produce arrays larger than `parameterLimit` regardless of `arrayLimit`, because each `a[]=value` consumes one parameter slot. The severity has been reduced accordingly.</p>
<p>### Details</p>
<p>The `arrayLimit` option only checked limits for indexed notation (`a[0]=1&amp;a[1]=2`) but did not enforce it for bracket notation (`a[]=1&amp;a[]=2`).</p>
<p>**Vulnerable code** (`lib/parse.js:159-162`):
```javascript
if (root === '[]' &amp;&amp; options.parseArrays) {
    obj = utils.combine([], leaf);  // No arrayLimit check
}
```</p>
<p>**Working code** (`lib/parse.js:175`):
```javascript
else if (index &lt;= options.arrayLimit) {  // Limit checked here
    obj = [];
    obj[index] = leaf;
}
```</p>
<p>The bracket notation handler at line 159 uses `utils.combine([], leaf)` without validating against `options.arrayLimit`, while indexed notation at line 175 checks `index &lt;= options.arrayLimit` before creating arrays.</p>
<p>### PoC</p>
<p>```javascript
const qs = require('qs');
const result = qs.parse('a[]=1&amp;a[]=2&amp;a[]=3&amp;a[]=4&amp;a[]=5&amp;a[]=6', { arrayLimit: 5 });
console.log(result.a.length);  // Output: 6 (should be max 5)
```</p>
<p>**Note on parameterLimit interaction…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6rw7-vpxm-498p"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-26-071-03</id>
    <title>ICSA-26-071-03 — Siemens SIDIS Prime</title>
    <updated>2026-10-02T11:05:30.109715+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters. An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing. An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key. Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key. There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above. Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-26-071-03"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-15284</id>
    <title>msrc_CVE-2025-15284 — arrayLimit bypass in bracket notation allows DoS via memory exhaustion</title>
    <updated>2026-10-02T11:05:30.109819+00:00</updated>
    <content>msrc_CVE-2025-15284</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-15284"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0034</id>
    <title>NCSC-2026-0034 — Kwetsbaarheden verholpen in Atlassian producten</title>
    <updated>2026-10-02T11:05:30.109836+00:00</updated>
    <content>NCSC-2026-0034</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0034"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:0261</id>
    <title>RHSA-2026:0261 — Red Hat Security Advisory: Red Hat Developer Hub 1.7.4 release.</title>
    <updated>2026-10-02T11:05:30.109885+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications qs: qs: Denial of Service via improper input validation in array parsing glob: glob: Command Injection Vulnerability via Malicious Filenames node-jws: auth0/node-jws: Improper signature verification in HS256 algorithm node-forge: node-forge ASN.1 Unbounded Recursion</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:0261"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:18480</id>
    <title>RHSA-2026:18480 — Red Hat Security Advisory: linux-sgx security update</title>
    <updated>2026-10-02T11:05:30.109908+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>lodash: prototype pollution in _.unset and _.omit functions qs: qs: Denial of Service via improper input validation in array parsing node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:18480"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:18480</id>
    <title>RLSA-2026:18480 — Important: linux-sgx security update</title>
    <updated>2026-10-02T11:05:30.109931+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: linux-sgx</p>
<p>The Intel SGX SDK is a collection of APIs, libraries, documentations and tools that allow software developers to create and debug Intel SGX enabled applications in C/C++.</p>
<p>Security Fix(es):</p>
<p>* qs: qs: Denial of Service via improper input validation in array parsing (CVE-2025-15284)</p>
<p>* node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives (CVE-2026-23745)</p>
<p>* node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition (CVE-2026-23950)</p>
<p>* lodash: prototype pollution in _.unset and _.omit functions (CVE-2025-13465)</p>
<p>* node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check (CVE-2026-24842)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the Rocky Linux 10 Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:18480"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-485750</id>
    <title>SSA-485750 — SSA-485750: Multiple Vulnerabilities in SIDIS Prime Before V4.0.800</title>
    <updated>2026-10-02T11:05:30.109962+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters. An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing. An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key. Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key. There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above. Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-485750"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-15284</id>
    <title>UBUNTU-CVE-2025-15284</title>
    <updated>2026-10-02T11:05:30.110060+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: node-qs, Ubuntu:16.04:LTS: node-qs, Ubuntu:18.04:LTS: node-qs, Ubuntu:Pro:20.04:LTS: node-qs, Ubuntu:22.04:LTS: node-qs, Ubuntu:24.04:LTS: node-qs, Ubuntu:25.10: node-qs, Ubuntu:26.04:LTS: node-qs</p>
<p>Improper Input Validation vulnerability in qs (parse modules) allows HTTP DoS.This issue affects qs: &lt; 6.14.1. Summary The arrayLimit option in qs did not enforce limits for bracket notation (a[]=1&amp;a[]=2), only for indexed notation (a[0]=1). This is a consistency bug; arrayLimit should apply uniformly across all array notations. Note: The default parameterLimit of 1000 effectively mitigates the DoS scenario originally described. With default options, bracket notation cannot produce arrays larger than parameterLimit regardless of arrayLimit, because each a[]=valueconsumes one parameter slot. The severity has been reduced accordingly. Details The arrayLimit option only checked limits for indexed notation (a[0]=1&amp;a[1]=2) but did not enforce it for bracket notation (a[]=1&amp;a[]=2). Vulnerable code (lib/parse.js:159-162): if (root === '[]' &amp;&amp; options.parseArrays) {     obj = utils.combine([], leaf);  // No arrayLimit check } Working code (lib/parse.js:175): else if (index &lt;= options.arrayLimit) {  // Limit checked here     obj = [];     obj[index] = leaf; } The bracket notation handler at line 159 uses utils.combine([], leaf) without validating against options.arrayLimit, while indexed notation at line 175 checks index &lt;= options.arrayLimit before creating arrays. PoC const qs = require('qs'); const result = qs.parse('a[]=1&amp;a[]=2&amp;a[]=3&amp;a[]=4&amp;a[]=5&amp;a[]=6', { arrayLimit: 5 }); console.log(result.a.length);  // Output: 6 (should be max 5) Note on parameterLimit interaction: The origin…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-15284"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-009</id>
    <title>VDE-2026-009 — JUMO: Multiple products affected by nodejs vulnerability</title>
    <updated>2026-10-02T11:05:30.110106+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability in the REST API of the JUMO device allows an attacker to trigger a denial‑of‑service (DoS) condition. Due to an incorrect implementation of the arrayLimit option in the Node.js qs module, limits for incoming request parameters are not properly enforced. As a result, an attacker can send specially crafted requests containing excessively large or deeply nested arrays, causing the web server to become unresponsive. This condition leads to a crash of the web server, followed by an automatic restart of the device.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-009"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0105</id>
    <title>WID-SEC-W-2026-0105 — Red Hat Developer Hub: Mehrere Schwachstellen</title>
    <updated>2026-10-02T11:05:30.110128+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Red Hat Developer Hub ausnutzen, um einen Denial of Service Angriff durchzuführen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen und Daten zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0105"/>
  </entry>
</feed>
