<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T12:07:38.594443+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-07453</id>
    <title>bdu:2025-07453</title>
    <updated>2026-10-02T12:07:38.785909+00:00</updated>
    <content>bdu:2025-07453</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-07453"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0724</id>
    <title>certfr-2025-avi-0724 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T12:07:38.785952+00:00</updated>
    <content>certfr-2025-avi-0724</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0724"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-245622</id>
    <title>EUVD-2026-245622</title>
    <updated>2026-10-02T12:07:38.785971+00:00</updated>
    <content>EUVD-2026-245622</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-245622"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-6545</id>
    <title>fkie_cve-2025-6545</title>
    <updated>2026-10-02T12:07:38.785983+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation. This vulnerability is associated with program files lib/to-buffer.Js.</p>
<p>This issue affects pbkdf2: from 3.0.10 through 3.1.2.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-6545"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-h7cp-r72f-jxh6</id>
    <title>GHSA-h7cp-r72f-jxh6 — pbkdf2 returns predictable uninitialized/zero-filled memory for non-normalized or unimplemented algos</title>
    <updated>2026-10-02T12:07:38.786013+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: pbkdf2</p>
<p>### Summary</p>
<p>This affects both:
 1. Unsupported algos (e.g. `sha3-256` / `sha3-512` / `sha512-256`)
 2. Supported but non-normalized algos (e.g. `Sha256` / `Sha512` / `SHA1` / `sha-1` / `sha-256` / `sha-512`)</p>
<p>All of those work correctly in Node.js, but this polyfill silently returns highly predictable ouput</p>
<p>Under Node.js (only with `pbkdf2/browser` import, unlikely) / Bun (`pbkdf2` top-level import is affected), the memory is not zero-filled but is uninitialized, as `Buffer.allocUnsafe` is used</p>
<p>Under browsers, it just returns zero-filled buffers
(Which is also critical, those are completely unacceptable as kdf output and ruin security)</p>
<p>### Were you affected?</p>
<p>The full list of arguments that were **not** affected were literal:
 * `'md5'`
 * `'sha1'`
 * `'sha224'`
 * `'sha256'`
 * `'sha384'`
 * `'sha512'`
 * `'rmd160'`
 * `'ripemd160'`</p>
<p>Any other arguments, e.g. representation variations of the above ones like `'SHA-1'`/`'sha-256'`/`'SHA512'` or  different algos like `'sha3-512'`/`'blake2b512'`, while supported on Node.js `crypto` module, returned predictable output on `pbkdf2` (or `crypto` browser/bundlers polyfill)</p>
<p>---</p>
<p>Beware of packages re-exporting this under a different signature, like (abstract):
```js
const crypto = require('crypto')
module.exports.deriveKey = (algo, pass, salt) =&gt; crypto.pbkdf2Sync(pass, salt, 2048, 64, algo)
```</p>
<p>In this case, the resulting `deriveKey` method is also affected (to the same extent / conditions as listed here).</p>
<p>### Environments</p>
<p>T…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-h7cp-r72f-jxh6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15280-1</id>
    <title>openSUSE-SU-2025:15280-1 — python311-pytest-html-4.1.1-6.1 on GA media</title>
    <updated>2026-10-02T12:07:38.786081+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python311-pytest-html-4.1.1-6.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15280-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:10738</id>
    <title>RHSA-2025:10738 — Red Hat Security Advisory: Kiali 2.4.7 for Red Hat OpenShift Service Mesh 3.0</title>
    <updated>2026-10-02T12:07:38.786100+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>pbkdf2: pbkdf2 silently returns predictable key material pbkdf2: pbkdf2 silently returns static keys</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:10738"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-6545</id>
    <title>UBUNTU-CVE-2025-6545</title>
    <updated>2026-10-02T12:07:38.786117+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:18.04:LTS: node-pbkdf2, Ubuntu:Pro:20.04:LTS: node-pbkdf2, Ubuntu:Pro:22.04:LTS: node-pbkdf2, Ubuntu:Pro:24.04:LTS: node-pbkdf2</p>
<p>Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation. This vulnerability is associated with program files lib/to-buffer.Js. This issue affects pbkdf2: from 3.0.10 through 3.1.2.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-6545"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1409</id>
    <title>WID-SEC-W-2025-1409 — IBM App Connect Enterprise: Mehrere Schwachstellen ermöglichen Manipulation von Daten</title>
    <updated>2026-10-02T12:07:38.786140+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Daten zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1409"/>
  </entry>
</feed>
